SB2026091765 - Out-of-bounds write in Linux kernel usb cx231xx driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89894)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a heap-based out-of-bounds write.
The vulnerability exists due to a heap-based buffer overflow in cx231xx VBI buffer handling in cx231xx_do_vbi_copy() when changing video geometry while a VBI stream is running. A local user can allocate a small VBI buffer and change the video width or standard to write past the allocated buffer.
Exploitation requires the device to deliver a field-2 VBI payload.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9
- https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d
- https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d
- https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f
- https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0
- https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a
- https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd
- https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf