PT-2026-93535 · Linux · Linux Kernel

CVE-2026-89894

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A heap out-of-bounds write exists in the cx231xx driver. The functions vidioc s fmt vid cap() and vidioc s std() allow changes to device-wide geometry, specifically dev->width and dev->norm, while only checking if the video queue dev->vidq is busy. However, the VBI queue dev->vbiq shares this geometry. An application can allocate a small VBI plane and then increase dev->width or change dev->norm via the video node while the VBI stream is active. When cx231xx do vbi copy() recomputes the destination offset using the updated larger geometry, it performs a memcpy() that writes past the end of the previously allocated smaller plane. The offset of this write is attacker-controlled, and the data originates from the device.
Recommendations As a temporary mitigation, restrict the use of the vidioc s fmt vid cap() and vidioc s std() functions to modify geometry while VBI streams are active. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101478
CVE-2026-89894
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel