CVE-2026-46058 PUBLISHED

media: amphion: Fix race between m2m job_abort and device_run

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

media: amphion: Fix race between m2m job_abort and device_run

Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context.

Race sequence: v4l2_m2m_try_run(): v4l2_m2m_ctx_release(): lock/unlock v4l2_m2m_cancel_job() job_abort() v4l2_m2m_job_finish() kfree(m2m_ctx) <- frees ctx device_run() <- use-after-free crash at 0x538

Crash trace: Unable to handle kernel read from unreadable memory at virtual address 0000000000000538 v4l2_m2m_try_run+0x78/0x138 v4l2_m2m_device_run_work+0x14/0x20

The amphion vpu driver does not rely on the m2m framework's device_run callback to perform encode/decode operations.

Fix the race by preventing m2m framework job scheduling entirely: - Add job_ready callback returning 0 (no jobs ready for m2m framework) - Remove job_abort callback to avoid the race condition

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3cd084519c6f91cbef9d604bcf26844fa81d4922 to 42dc622776f3ce1a6c31b13bdc686f7295e3b323 (excl.)
  • affected from 3cd084519c6f91cbef9d604bcf26844fa81d4922 to da4f46c5cf1d26e6b09418ad453e152f2e75a02c (excl.)
  • affected from 3cd084519c6f91cbef9d604bcf26844fa81d4922 to fdc150dac1adb9a98be9d6956cff0348838b024a (excl.)
  • affected from 3cd084519c6f91cbef9d604bcf26844fa81d4922 to 6be2cb75bc1300080cfc8051579f22efae9401f7 (excl.)
  • affected from 3cd084519c6f91cbef9d604bcf26844fa81d4922 to 8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.18 is affected
  • unaffected from 0 to 5.18 (excl.)
  • unaffected from 6.6.140 to 6.6.* (incl.)
  • unaffected from 6.12.86 to 6.12.* (incl.)
  • unaffected from 6.18.27 to 6.18.* (incl.)
  • unaffected from 7.0.4 to 7.0.* (incl.)
  • unaffected from 7.1-rc1 to * (incl.)

References