« Volver al listado

CVE-2026-89875

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

media: ti: vpe: quiesce overflow recovery before freeing streams

The VIP overflow recovery worker is armed from the hardirq handler when a FIFO overflow is detected, and the list-complete path looks the stream up through the VPDMA list private pointer. Both keep touching stream, port and device state; the recovery worker also resets the parser and VPDMA, repopulates the descriptor list, and re-enables the per-list IRQs.

vip_stop_streaming() masks and clears the per-list IRQs, but it neither synchronizes the hardirq handler nor disables recovery_work.

Leer descripción completaMostrar menos

An overflow IRQ that has already queued recovery_work, or a list-complete IRQ in flight when the stream is torn down, can therefore still dereference the stream after its resources are released: the descriptor list is freed by vip_release_stream() on file release, and the stream itself by free_stream() on unbind/remove.

Drain the recovery worker and the IRQ handler at both teardown points through a shared vip_quiesce_stream() helper, before any stream-owned resource is released. disable_work_sync() cancels pending recovery_work, drains a running instance, and raises its disable depth, so a subsequent schedule_work() issued by a racing IRQ handler is rejected at the workqueue scheduler: recovery_work cannot be requeued after disable_work_sync() takes effect. The worker may still re-enable the per-list IRQs before disable_work_sync() returns; disable_irqs() then masks those sources and synchronize_irq() waits for any in-flight handler that still dereferences stream state. In vip_stop_streaming() the helper runs before the parser is stopped, since a worker drained by disable_work_sync() may re-enable the parser before exiting and would otherwise undo the stop. recovery_work is created disabled and enabled in vip_start_streaming() before IRQs, pairing the enable with the teardown disable across the streaming lifecycle.

This issue was found by an in-house static analysis tool and confirmed by manual code review.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local de escalada de privilegios en kernel Linux (AV:L, PR:L) por condición de carrera en gestor de recuperación de overflow. Permite DoS mediante denegación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89875",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fc2873aa4a21355593b55eb49ff534d31f81c584",
              "lessThan": "fd5b4a14c87b21e1c9eaee603b01bb7fa7db45c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fc2873aa4a21355593b55eb49ff534d31f81c584",
              "lessThan": "aeaacc3001449d44b4ab7da56331121d1f3b137b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/platform/ti/vpe/vip.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/platform/ti/vpe/vip.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:55.757",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/aeaacc3001449d44b4ab7da56331121d1f3b137b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fd5b4a14c87b21e1c9eaee603b01bb7fa7db45c8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ti: vpe: quiesce overflow recovery before freeing streams\n\nThe VIP overflow recovery worker is armed from the hardirq handler when a\nFIFO overflow is detected, and the list-complete path looks the stream up\nthrough the VPDMA list private pointer. Both keep touching stream, port\nand device state; the recovery worker also resets the parser and VPDMA,\nrepopulates the descriptor list, and re-enables the per-list IRQs.\n\nvip_stop_streaming() masks and clears the per-list IRQs, but it neither\nsynchronizes the hardirq handler nor disables recovery_work. An overflow\nIRQ that has already queued recovery_work, or a list-complete IRQ in\nflight when the stream is torn down, can therefore still dereference the\nstream after its resources are released: the descriptor list is freed by\nvip_release_stream() on file release, and the stream itself by\nfree_stream() on unbind/remove.\n\nDrain the recovery worker and the IRQ handler at both teardown points\nthrough a shared vip_quiesce_stream() helper, before any stream-owned\nresource is released. disable_work_sync() cancels pending recovery_work,\ndrains a running instance, and raises its disable depth, so a subsequent\nschedule_work() issued by a racing IRQ handler is rejected at the\nworkqueue scheduler: recovery_work cannot be requeued after\ndisable_work_sync() takes effect. The worker may still re-enable the\nper-list IRQs before disable_work_sync() returns; disable_irqs() then\nmasks those sources and synchronize_irq() waits for any in-flight handler\nthat still dereferences stream state. In vip_stop_streaming() the helper\nruns before the parser is stopped, since a worker drained by\ndisable_work_sync() may re-enable the parser before exiting and would\notherwise undo the stop. recovery_work is created disabled and enabled in\nvip_start_streaming() before IRQs, pairing the enable with the teardown\ndisable across the streaming lifecycle.\n\nThis issue was found by an in-house static analysis tool and confirmed\nby manual code review."
    }
  ],
  "lastModified": "2026-09-16T15:18:14.437",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}