media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
Published Apr 22, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
MEDIA_REQUEST_IOC_REINIT can run concurrently with VIDIOC_REQBUFS(0) queue teardown paths. This can race request object cleanup against vb2 queue cancellation and lead to use-after-free reports.
We already serialize request queueing against STREAMON/OFF with req_queue_mutex. Extend that serialization to REQBUFS, and also take the same mutex in media_request_ioctl_reinit() so REINIT is in the same exclusion domain.
This keeps request cleanup and queue cancellation from running in parallel for request-capable devices.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.20StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.20
- Version 5.10.253StatusunaffectedConstraints<=5.10.*
- Version 5.15.203StatusunaffectedConstraints<=5.15.*
- Version 6.1.168StatusunaffectedConstraints<=6.1.*
- Version 6.12.80StatusunaffectedConstraints<=6.12.*
- Version 6.18.21StatusunaffectedConstraints<=6.18.*
- Version 6.19.11StatusunaffectedConstraints<=6.19.*
- Version 6.6.131StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.20.1 · < 5.10.253
- ≥ 5.11 · < 5.15.203
- ≥ 5.16 · < 6.1.168
- ≥ 6.2 · < 6.6.131
- ≥ 6.7 · < 6.12.80
- ≥ 6.13 · < 6.18.21
- ≥ 6.19 · < 6.19.11
- 4.20
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat acknowledges this upstream media/V4L2 fix. The defect is a concurrency bug between MEDIA_REQUEST_IOC_REINIT and REQBUFS teardown that could corrupt request and vb2 queue lifetimes. Customers should consume corrected kernels through their product errata. Exploitation requires a local user able to exercise request-capable media nodes.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.17% (0.00171) | 5.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.13% (0.00126) | 2.56th | v5 (v2026.06.15) |
| Apr 23, 2026 | 0.02% (0.00024) | 6.79th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/security/cve/CVE-2026-31473 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460734 Issue Tracking
- https://git.kernel.org/stable/c/1a0d9083c24fbd5d22f7100f09d11e4d696a5f01 Patch
- https://git.kernel.org/stable/c/2c685e99efb3b3bd2b78699fba6b1cf321975db0 Patch
- https://git.kernel.org/stable/c/331242998a7ade5c2f65e14988901614629f3db5 Patch
- https://git.kernel.org/stable/c/585fd9a2063dacce8b2820f675ef23d5d17434c5 Patch
- https://git.kernel.org/stable/c/72b9e81e0203f03c40f3adb457f55bd4c8eb112d Patch
- https://git.kernel.org/stable/c/bef4f4a88b73e4cc550d25f665b8a9952af22773 Patch
- https://git.kernel.org/stable/c/cf2023e84f0888f96f4b65dc0804e7f3651969c1 Patch
- https://git.kernel.org/stable/c/d8549a453d5bdc0a71de66ad47a1106703406a56 Patch
- https://lore.kernel.org/linux-cve-announce/2026042255-CVE-2026-31473-fad0@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-31473
- https://www.cve.org/CVERecord?id=CVE-2026-31473
Change history (0)
No recorded changes yet.