PT-2026-93535 · Linux · Linux Kernel
CVE-2026-89894
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A heap out-of-bounds write exists in the cx231xx driver. The functions
vidioc s fmt vid cap() and vidioc s std() allow changes to device-wide geometry, specifically dev->width and dev->norm, while only checking if the video queue dev->vidq is busy. However, the VBI queue dev->vbiq shares this geometry. An application can allocate a small VBI plane and then increase dev->width or change dev->norm via the video node while the VBI stream is active. When cx231xx do vbi copy() recomputes the destination offset using the updated larger geometry, it performs a memcpy() that writes past the end of the previously allocated smaller plane. The offset of this write is attacker-controlled, and the data originates from the device.Recommendations
As a temporary mitigation, restrict the use of the
vidioc s fmt vid cap() and vidioc s std() functions to modify geometry while VBI streams are active. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel