PT-2026-93529 · Linux · Linux Kernel

CVE-2026-89888

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the ov02a10 check hwcfg() function. The function calls fwnode handle put(ep) immediately after allocating and parsing the endpoint, but then attempts to use the same ep handle in a subsequent call to fwnode property read u32(). Additionally, the function incorrectly assigns the result of reading the optional ovti,mipi-clock-voltage property to the ret variable, which can cause the probe process to fail if the property is missing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101361
CVE-2026-89888
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel