CVE-2026-89899
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-89899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: media: cec: disable delayed work before freeing an interrupted transmit cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in wait_for_completion_killable(). If that wait is interrupted by a signal, cancel_delayed_work_sync() can run before the CEC kthread arms the reply timeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts(). The work is then armed after the cancel, and the data is freed with its delayed_work still pending: ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout Use disable_delayed_work_sync(): it cancels the work and disables it, so the later schedule_delayed_work() becomes a no-op and the work cannot be re-armed. The data is freed right after, so it need not be re-enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-07
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 490d84f6d73c12f4204241cff8651eed60aae914
Linux Linux 490d84f6d73c12f4204241cff8651eed60aae914
Linux Linux 490d84f6d73c12f4204241cff8651eed60aae914
Linux Linux 490d84f6d73c12f4204241cff8651eed60aae914
Linux Linux e448dfd6d3ec944411f6575bc24e4f8baa1e297f
Linux Linux 2781b86d7e45de09befa5ace296b66787146561f
Linux Linux 4.18.19
Linux Linux 4.19.2
Linux Linux 4.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart