CVE-2026-89894
In the Linux kernel, the following vulnerability has been resolved:
media: cx231xx: reject geometry changes while the VBI queue is busy
vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide dev->width / dev->norm but only refuse the change when the *video* queue (dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry: cx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm, the VBI videobuf2 plane is sized from dev->width / dev->norm in vbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then recomputes the destination offset from the *live* dev->width and the latched lines_per_field on every URB completion:
Leer descripción completaMostrar menos
Because the VBI node shares video_ioctl_ops with the video node, an application can size a small VBI plane (REQBUFS/QBUF with a small width, or with the NTSC standard), then enlarge dev->width (or switch dev->norm to PAL) through the video node while the VBI stream is running -- the change is allowed because only dev->vidq is checked -- and let the device deliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the offset with the larger geometry and memcpy()s past the end of the smaller plane that was already allocated, a heap out-of-bounds write whose offset is attacker-chosen and whose contents come from the device. The per-field guard in cx231xx_copy_vbi_line() does not help: it bounds the copy against the latched lines_per_field, not the plane's real capacity, and vb2 does not re-run buf_prepare() for an already prepared buffer.
Refuse the format/standard change when the VBI queue is busy as well, so the geometry cannot change underneath an allocated VBI buffer.
Detalles técnicos trazas, registros y código del informe original
offset = lines_completed * (dev->width << 1) + ...; if (dma_q->current_field == 2) offset += dev->width * 2 * dma_q->lines_per_field; memcpy(plane + offset, p_buffer, lencopy);
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1565.001Stored Data Manipulationimpact75 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Escalada local en kernel Linux (PR:L) mediante cambio de geometría de buffer mientras VBI está activo. Escritura de heap fuera de límites con contenido controlado por dispositivo.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9
- https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d
- https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d
- https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f
- https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0
- https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a
- https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd
- https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89894",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "aa3314506deb9703bcf0e889db08959440228fbf",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "90d50648af36a1fbf5dbc99238de6fd0e58a13e0",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "a5dd3d7fba358ff9486f3f51b2a9038348c0970a",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "1d1079db8d1807e259a1d2679ed314949797aad9",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "7087bef6510c7df5df0b19192633b8ecc0f33a6f",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "a636c72c7f522d984fa498fc0631f33a2d0be3fd",
"versionType": "git"
},
{
"status": "affected",
"version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
"lessThan": "627a121c15fe05a541f44d86016294b80bada75d",
"versionType": "git"
}
],
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-video.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-video.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:16:58.127",
"references": [
{
"url": "https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: reject geometry changes while the VBI queue is busy\n\nvidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide\ndev->width / dev->norm but only refuse the change when the *video* queue\n(dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry:\ncx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm,\nthe VBI videobuf2 plane is sized from dev->width / dev->norm in\nvbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then\nrecomputes the destination offset from the *live* dev->width and the\nlatched lines_per_field on every URB completion:\n\n\toffset = lines_completed * (dev->width << 1) + ...;\n\tif (dma_q->current_field == 2)\n\t\toffset += dev->width * 2 * dma_q->lines_per_field;\n\tmemcpy(plane + offset, p_buffer, lencopy);\n\nBecause the VBI node shares video_ioctl_ops with the video node, an\napplication can size a small VBI plane (REQBUFS/QBUF with a small width,\nor with the NTSC standard), then enlarge dev->width (or switch dev->norm\nto PAL) through the video node while the VBI stream is running -- the\nchange is allowed because only dev->vidq is checked -- and let the device\ndeliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the\noffset with the larger geometry and memcpy()s past the end of the smaller\nplane that was already allocated, a heap out-of-bounds write whose offset\nis attacker-chosen and whose contents come from the device. The\nper-field guard in cx231xx_copy_vbi_line() does not help: it bounds the\ncopy against the latched lines_per_field, not the plane's real capacity,\nand vb2 does not re-run buf_prepare() for an already prepared buffer.\n\nRefuse the format/standard change when the VBI queue is busy as well, so\nthe geometry cannot change underneath an allocated VBI buffer."
}
],
"lastModified": "2026-09-16T15:18:15.790",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}