{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  media: nxp: imx8-isi: Fix use-after-free on remove  KASAN reports a slab-use-after-free in __media_entity_remove_link() during rmmod of imx8_isi:    BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650   Read of size 2 at addr ffff0000d47cb02a by task rmmod/724    Call trace:    __media_entity_remove_link+0x608/0x650    __media_entity_remove_links+0x78/0x144    __media_device_unregister_entity+0x150/0x280    media_device_unregister_entity+0x48/0x68    v4l2_device_unregister_subdev+0x158/0x300    v4l2_async_unbind_subdev_one+0x22c/0x358    v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0    v4l2_async_nf_unregister+0x5c/0x14c    mxc_isi_remove+0x124/0x2a0 [imx8_isi]    Allocated by task 249:    __kmalloc_noprof+0x27c/0x690    mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]    Freed by task 724:    kfree+0x1e4/0x5b0    mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]    mxc_isi_remove+0x11c/0x2a0 [imx8_isi]  The problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup() before mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media entity pads, but the subsequent v4l2 cleanup still tries to remove media links that reference those pads.  Fix this by calling mxc_isi_v4l2_cleanup() before mxc_isi_crossbar_cleanup() to ensure all media entities are properly unregistered while the pads are still valid.",
  "id": "DEBIAN-CVE-2026-64421",
  "modified": "2026-09-14T16:47:31.417458123Z",
  "published": "2026-07-25T10:17:26.097Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64421"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64421"
  ]
}