PT-2026-93529 · Linux · Linux Kernel
CVE-2026-89888
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
ov02a10 check hwcfg() function. The function calls fwnode handle put(ep) immediately after allocating and parsing the endpoint, but then attempts to use the same ep handle in a subsequent call to fwnode property read u32(). Additionally, the function incorrectly assigns the result of reading the optional ovti,mipi-clock-voltage property to the ret variable, which can cause the probe process to fail if the property is missing.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel