PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80650 Linux CVE debrief

A use-after-free vulnerability and memory leak were found in the Linux kernel's media: atomisp: gc2235. The gc2235_probe() function incorrectly handles error paths, leading to potential use-after-free and memory leaks. This issue has been resolved with explicit unwind labels that free only the resources initialized at each point of failure. The vulnerability affects Linux kernel developers, maintainers, and users who rely on the media: atomisp: gc2235 functionality. They should assess exposure and prioritize verification of affected versions and deployments.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-10-05
Advisory published
2026-08-28
Advisory updated
2026-10-05

Who should care

Linux kernel developers, maintainers, and users who rely on the media: atomisp: gc2235 functionality should assess exposure and prioritize verification of affected versions and deployments.

Why it matters

A use-after-free vulnerability and memory leak in the Linux kernel's media: atomisp: gc2235 require verification of affected versions and deployments, and potential compensating controls or monitoring.

  • Verification of affected Linux kernel versions and deployments is required
  • Potential use-after-free and memory leaks may lead to system instability
  • Compensating controls or monitoring may be necessary until remediation is applied

Technical summary

The gc2235_probe() function in the Linux kernel's media: atomisp: gc2235 incorrectly handles error paths, leading to potential use-after-free and memory leaks. The issue has been resolved with explicit unwind labels that free only the resources initialized at each point of failure. Linux kernel developers and maintainers should assess exposure and prioritize verification of affected versions and deployments. They should verify the gc2235_probe() error path handling in Linux kernel code and assess the need for compensating controls or monitoring.

Defensive priority

Linux kernel developers and maintainers should assess exposure and prioritize verification of affected versions and deployments.

Recommended defensive actions

  • Review Linux kernel versions and deployments for potential exposure
  • Verify gc2235_probe() error path handling in Linux kernel code
  • Assess the need for compensating controls or monitoring
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but specific affected versions and exploitation details are not provided. Linux kernel developers and maintainers should verify the gc2235_probe() error path handling in Linux kernel code and assess the need for compensating controls or monitoring. The vulnerability has been resolved with explicit unwind labels that free only the resources initialized at each point of failure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80650 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80650

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80650 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80650

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/628f763aee0047ff44974388d6f70f75a763026b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d57e67ea48e4d095052f2b14d8dd7593621f862f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f614bf0a64aa1cb7444d152a96798a6bf1d49e1f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fdbb8e55578b4ab647fa58827a9dd8730d7f4add

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.