CVE-2026-89725
Received Received - Intake

Buffer Overflow in Linux Kernel CEC STM32 Driver

Vulnerability report for CVE-2026-89725, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent out-of-bounds write on RX overflow stm32_rx_done() appends each received CEC byte to rx_msg.msg[] using rx_msg.len as the write index, incrementing it on every RXBR (receive-byte-ready) interrupt without checking it against the buffer size: cec->rx_msg.msg[cec->rx_msg.len++] = val & 0xFF; rx_msg.msg[] is a fixed CEC_MAX_MSG_SIZE (16) byte array in struct cec_msg, and rx_msg.len is only reset on RXACKE/RXOVR or after a completed message (RXEND). The number of bytes received before RXEND is decided by the remote CEC device (it sets EOM), not by the driver. A peer that keeps sending bytes without ending the message drives RXBR repeatedly, pushing rx_msg.len past 16 and writing peer-controlled bytes out of bounds into the surrounding memory. This is reachable in normal operation once the driver has probed and receiving is enabled, from the IRQ thread, without any local privilege. The length check in the CEC core runs on the consumer side, after the byte has been stored, so it does not prevent the overflow. Bound the index in the driver before the store, as the other platform CEC drivers already do (e.g. tegra_cec), dropping the excess bytes of an overlong frame. Found by static analysis tool CodeQL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stm32 linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a buffer overflow vulnerability in the Linux kernel's media CEC subsystem for STM32 devices. The issue occurs in the stm32_rx_done() function where received CEC bytes are written to a fixed-size buffer without checking if the buffer is full. A remote device can send excessive bytes, causing the buffer index to exceed its limit and write data beyond the allocated memory.

Detection Guidance

This vulnerability is specific to the Linux kernel's CEC (Consumer Electronics Control) subsystem for STM32 devices. Detection requires checking the kernel version and examining the stm32_cec driver for the described out-of-bounds write condition. No network-specific detection commands are applicable as this is a local kernel driver issue.

Impact Analysis

This vulnerability could allow an attacker on the same network segment to cause memory corruption, potentially leading to crashes, privilege escalation, or arbitrary code execution on affected systems. It requires the vulnerable driver to be loaded and receiving enabled, but no local privileges are needed.

Compliance Impact

This vulnerability involves an out-of-bounds write in the Linux kernel's CEC subsystem, which could lead to memory corruption. While not directly related to data privacy, such memory corruption could potentially compromise system integrity, indirectly affecting compliance with standards like GDPR or HIPAA by weakening security controls that rely on stable system behavior.

Mitigation Strategies

Apply the Linux kernel patch that fixes this issue. Update your kernel to a version that includes the fix for the stm32_cec driver's RX overflow handling. If a patch is not yet available, disable the CEC functionality for STM32 devices in the kernel configuration until the fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89725. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart