Out-of-bounds write in Linux kernel - CVE-2026-89894
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a heap-based out-of-bounds write.
The vulnerability exists due to a heap-based buffer overflow in cx231xx VBI buffer handling in cx231xx_do_vbi_copy() when changing video geometry while a VBI stream is running. A local user can allocate a small VBI buffer and change the video width or standard to write past the allocated buffer.
Exploitation requires the device to deliver a field-2 VBI payload.
Affected software
How to mitigate CVE-2026-89894
External References
- https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9
- https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d
- https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d
- https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f
- https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0
- https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a
- https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd
- https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf