CVE-2026-93223EPSS p5.5%
CVE-2026-93223CVE-2026-93223
Description
In the Linux kernel, the following vulnerability has been resolved:
staging: media: tegra-video: fix of_node_put() on VIP parse errors
tegra_vip_channel_of_parse() initializes np from dev->of_node without
taking a reference, but its error paths drop one through the
err_node_put label. This underflows the refcount of the VIP device's
OF node when endpoint parsing fails on a malformed device tree.
The only reference the function takes on np is the success-path
of_node_get() stored in vip->chan.of_node, and that one is already
released by the tegra_vip_init() error path and by tegra_vip_exit().
Return errors directly instead of jumping to the bogus cleanup label.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 5.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |