Improper control of a resource through its lifetime in Linux kernel - CVE-2026-89866
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper runtime power-state handling in the Wave5 VPU decoder EOS handling when setting the EOS flag while the device is runtime suspended. A local user can issue a V4L2 stop command or stream-off operation to cause a denial of service.