« Volver al listado

CVE-2026-89894

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

media: cx231xx: reject geometry changes while the VBI queue is busy

vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide dev->width / dev->norm but only refuse the change when the *video* queue (dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry: cx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm, the VBI videobuf2 plane is sized from dev->width / dev->norm in vbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then recomputes the destination offset from the *live* dev->width and the latched lines_per_field on every URB completion:

Leer descripción completaMostrar menos

Because the VBI node shares video_ioctl_ops with the video node, an application can size a small VBI plane (REQBUFS/QBUF with a small width, or with the NTSC standard), then enlarge dev->width (or switch dev->norm to PAL) through the video node while the VBI stream is running -- the change is allowed because only dev->vidq is checked -- and let the device deliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the offset with the larger geometry and memcpy()s past the end of the smaller plane that was already allocated, a heap out-of-bounds write whose offset is attacker-chosen and whose contents come from the device. The per-field guard in cx231xx_copy_vbi_line() does not help: it bounds the copy against the latched lines_per_field, not the plane's real capacity, and vb2 does not re-run buf_prepare() for an already prepared buffer.

Refuse the format/standard change when the VBI queue is busy as well, so the geometry cannot change underneath an allocated VBI buffer.

Detalles técnicos trazas, registros y código del informe original
	offset = lines_completed * (dev->width << 1) + ...;
	if (dma_q->current_field == 2)
		offset += dev->width * 2 * dma_q->lines_per_field;
	memcpy(plane + offset, p_buffer, lencopy);

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Escalada local en kernel Linux (PR:L) mediante cambio de geometría de buffer mientras VBI está activo. Escritura de heap fuera de límites con contenido controlado por dispositivo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89894",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "aa3314506deb9703bcf0e889db08959440228fbf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "90d50648af36a1fbf5dbc99238de6fd0e58a13e0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "a5dd3d7fba358ff9486f3f51b2a9038348c0970a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "1d1079db8d1807e259a1d2679ed314949797aad9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "7087bef6510c7df5df0b19192633b8ecc0f33a6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "a636c72c7f522d984fa498fc0631f33a2d0be3fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab",
              "lessThan": "627a121c15fe05a541f44d86016294b80bada75d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/usb/cx231xx/cx231xx-video.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/usb/cx231xx/cx231xx-video.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:58.127",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: reject geometry changes while the VBI queue is busy\n\nvidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide\ndev->width / dev->norm but only refuse the change when the *video* queue\n(dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry:\ncx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm,\nthe VBI videobuf2 plane is sized from dev->width / dev->norm in\nvbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then\nrecomputes the destination offset from the *live* dev->width and the\nlatched lines_per_field on every URB completion:\n\n\toffset = lines_completed * (dev->width << 1) + ...;\n\tif (dma_q->current_field == 2)\n\t\toffset += dev->width * 2 * dma_q->lines_per_field;\n\tmemcpy(plane + offset, p_buffer, lencopy);\n\nBecause the VBI node shares video_ioctl_ops with the video node, an\napplication can size a small VBI plane (REQBUFS/QBUF with a small width,\nor with the NTSC standard), then enlarge dev->width (or switch dev->norm\nto PAL) through the video node while the VBI stream is running -- the\nchange is allowed because only dev->vidq is checked -- and let the device\ndeliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the\noffset with the larger geometry and memcpy()s past the end of the smaller\nplane that was already allocated, a heap out-of-bounds write whose offset\nis attacker-chosen and whose contents come from the device. The\nper-field guard in cx231xx_copy_vbi_line() does not help: it bounds the\ncopy against the latched lines_per_field, not the plane's real capacity,\nand vb2 does not re-run buf_prepare() for an already prepared buffer.\n\nRefuse the format/standard change when the VBI queue is busy as well, so\nthe geometry cannot change underneath an allocated VBI buffer."
    }
  ],
  "lastModified": "2026-09-16T15:18:15.790",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}