PT-2026-93534 · Linux · Linux Kernel
CVE-2026-89893
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
cx23885 media driver. The netup ci exit() function frees the netup ci state while the netup read ci status() work item may still be pending or executing on the system workqueue. Because the worker uses container of() to obtain and dereference the state, it must not outlive the state. Although cx23885 finidev() calls free irq() during removal, this only prevents new interrupt handlers from running and does not drain previously queued work, allowing the worker to execute after the state has been freed.Recommendations
Call
cancel work sync() before executing dvb ca en50221 release() and kfree() to ensure all pending work is completed before the state is freed.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel