OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97513

HIGH · CVSS 7.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability exists in the Linux kernel's media subsystem, specifically in the wave5 driver, where a use-after-free condition can occur if an IRQ thread acquires a spinlock between the release of the m2m_ctx and the removal of the stream instance from the active list. This can lead to a null pointer dereference, potentially resulting in system instability or crashes. Linux system administrators and developers utilizing affected versions of the kernel should prioritize applying patches to mitigate this risk.

CVE
CVE-2026-97513
Severity
HIGH
CVSS
7.8
EPSS
0.11%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Release m2m_ctx after Instance Removed from List Possible use after free if IRQ thread manages to obtain spinlock between m2m_ctx release and wave5_release function removing stream instance from list of active instances. The IRQ thread looks for the m2m_ctx which is freed so null pointer dereference occurs.