CVE-2026-89599
Received Received - Intake

omapfb DSI CM Panel Lock Initialization Flaw

Vulnerability report for CVE-2026-89599, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display dsicm_probe() registers the display before initializing ddata->lock. Once omapdss_register_display() publishes the display, another consumer can reach a dsicm callback that takes this mutex while it is still uninitialized. Initialize the mutex before registering the display so the published callbacks always see a valid lock.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper initialization of a lock in the omapfb panel driver. The dsicm_probe function registers a display before initializing the lock for the display data. This allows another process to access a callback that uses the uninitialized mutex, potentially causing undefined behavior or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's fbdev subsystem, particularly in the omapfb driver. Detection requires checking kernel logs for omapfb-related errors or kernel panics during display initialization. Commands like dmesg | grep omapfb or journalctl -k | grep omapfb may help identify issues.

Impact Analysis

If exploited, this could lead to system instability, crashes, or unexpected behavior in systems using the affected Linux kernel component. It may allow unauthorized access or manipulation of display-related functions, though practical exploitation depends on system configuration.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel driver issue related to improper mutex initialization in the omapfb display subsystem, which could lead to race conditions but does not involve data handling or privacy concerns.

Mitigation Strategies

Update the Linux kernel to a patched version where this issue is resolved. Monitor vendor advisories for kernel updates. If immediate patching is not possible, disable the omapfb driver or the affected panel-dsi-cm module to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89599. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart