Integer overflow in Linux kernel - CVE-2026-89876
Published: September 17, 2026
Vulnerability identifier: #VU150416
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89876
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to trigger undefined behavior.
The vulnerability exists due to an integer overflow in the tda18250 media driver when exp equals zero. A local user can cause exp to equal zero to trigger undefined behavior.
Affected software
Linux kernel
How to mitigate CVE-2026-89876
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/0e0fbdb4c9381e2ea647a3fe3bf39bdb02ea5b73
- https://git.kernel.org/stable/c/3e5568d554c5f6da2cbba45684295927ebefd943
- https://git.kernel.org/stable/c/4e21f0e5696d3148b183c7e21dd44f7dec0d07ef
- https://git.kernel.org/stable/c/593b1172e5d548581dfdb9a63713088f5dfab255
- https://git.kernel.org/stable/c/6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4
- https://git.kernel.org/stable/c/7c62bd653563939ff0d0fdfd4b8c73c4f97a1dcc
- https://git.kernel.org/stable/c/cf8e3b3d7d9a6a96f4df6246e2e14b32f58d889e
- https://git.kernel.org/stable/c/f1ba602afd5ee6609fd71a0d112d18e8447a485f