{"api_version":"1","generated_at":"2026-10-01T19:11:56+00:00","cve":"CVE-2026-89898","urls":{"html":"https://cve.report/CVE-2026-89898","api":"https://cve.report/api/cve/CVE-2026-89898.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89898","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89898"},"summary":{"title":"media: cec: extron-da-hd-4k-plus: add sanity check","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: extron-da-hd-4k-plus: add sanity check\n\nAdd check to prevent overflowing msg.msg[] in case the incoming data\nis malformed.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:58","updated_at":"2026-09-16 15:18:16"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/673611cc2ab9769929644ce879f7ea34932a3011","name":"https://git.kernel.org/stable/c/673611cc2ab9769929644ce879f7ea34932a3011","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/00c13b4ab481a09d915d099815cff1b10926ddd9","name":"https://git.kernel.org/stable/c/00c13b4ab481a09d915d099815cff1b10926ddd9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3","name":"https://git.kernel.org/stable/c/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7ad2fec276946a0dedfa54eb26fc38c4fc6a6034","name":"https://git.kernel.org/stable/c/7ad2fec276946a0dedfa54eb26fc38c4fc6a6034","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89898","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89898","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 056f2821b631df2b94d3b017fd1e1eef918ed98d 00c13b4ab481a09d915d099815cff1b10926ddd9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 056f2821b631df2b94d3b017fd1e1eef918ed98d 673611cc2ab9769929644ce879f7ea34932a3011 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 056f2821b631df2b94d3b017fd1e1eef918ed98d 7ad2fec276946a0dedfa54eb26fc38c4fc6a6034 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 056f2821b631df2b94d3b017fd1e1eef918ed98d abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/cec/usb/extron-da-hd-4k-plus/extron-da-hd-4k-plus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"00c13b4ab481a09d915d099815cff1b10926ddd9","status":"affected","version":"056f2821b631df2b94d3b017fd1e1eef918ed98d","versionType":"git"},{"lessThan":"673611cc2ab9769929644ce879f7ea34932a3011","status":"affected","version":"056f2821b631df2b94d3b017fd1e1eef918ed98d","versionType":"git"},{"lessThan":"7ad2fec276946a0dedfa54eb26fc38c4fc6a6034","status":"affected","version":"056f2821b631df2b94d3b017fd1e1eef918ed98d","versionType":"git"},{"lessThan":"abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3","status":"affected","version":"056f2821b631df2b94d3b017fd1e1eef918ed98d","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/media/cec/usb/extron-da-hd-4k-plus/extron-da-hd-4k-plus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.12"},{"lessThan":"6.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: extron-da-hd-4k-plus: add sanity check\n\nAdd check to prevent overflowing msg.msg[] in case the incoming data\nis malformed."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:A - extron_process_received() hex-decodes Ceci/Ceco lines the Extron DA HD 4K Plus reports from its HDMI ports over USB-serial; a malicious HDMI-CEC source on the same splitter bus (conference-room laptop, signage player) can supply those frames, with a USB gadget impersonating the Extron only an extra physical path.\nAC:L - A crafted Ceci/Ceco line of more than 16 %XX triplets deterministically writes past msg.msg[16]; the attacker fully controls the HDMI-CEC or USB-serial payload, and no race or attacker-uncontrollable memory layout is required.\nPR:N - HDMI-CEC and the Extron USB-serial reports are parsed in extron_interrupt() with no host authentication; an adjacent HDMI device or malicious USB ACM gadget needs no account or capability on the Linux host.\nUI:N - Once the Extron is bound via serport, incoming serial lines are parsed automatically in the interrupt handler; an already-connected HDMI source can trigger the overflow without a victim opening a file or clicking.\nS:U - The overflow corrupts only the host kernel that runs this CEC USB driver and does not cross a VM, IOMMU, or other separate security authority.\nC:H - Attacker-chosen hex bytes are written past the 16-byte on-stack msg.msg[] array (a 256-byte line yields up to ~82 decoded bytes), corrupting kernel stack contents and enabling disclosure of adjacent kernel memory.\nI:H - The same out-of-bounds stores smash the kernel stack frame, including saved control data and the return address, enabling control-flow hijacking and arbitrary kernel writes.\nA:H - Overflowing the on-stack cec_msg produces a kernel oops or panic from stack-canary abort or corrupted control data, so the host can be crashed at will."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:39:47.656Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/00c13b4ab481a09d915d099815cff1b10926ddd9"},{"url":"https://git.kernel.org/stable/c/673611cc2ab9769929644ce879f7ea34932a3011"},{"url":"https://git.kernel.org/stable/c/7ad2fec276946a0dedfa54eb26fc38c4fc6a6034"},{"url":"https://git.kernel.org/stable/c/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3"}],"title":"media: cec: extron-da-hd-4k-plus: add sanity check","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89898","datePublished":"2026-09-16T10:31:58.901Z","dateReserved":"2026-09-11T19:38:34.773Z","dateUpdated":"2026-09-16T14:39:47.656Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:58","lastModifiedDate":"2026-09-16 15:18:16","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89898","Ordinal":"1","Title":"media: cec: extron-da-hd-4k-plus: add sanity check","CVE":"CVE-2026-89898","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89898","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: extron-da-hd-4k-plus: add sanity check\n\nAdd check to prevent overflowing msg.msg[] in case the incoming data\nis malformed.","Type":"Description","Title":"media: cec: extron-da-hd-4k-plus: add sanity check"}]}}}