Description
In the Linux kernel, the following vulnerability has been resolved:

media: cec: stm32: prevent out-of-bounds write on RX overflow

stm32_rx_done() appends each received CEC byte to rx_msg.msg[] using
rx_msg.len as the write index, incrementing it on every RXBR
(receive-byte-ready) interrupt without checking it against the buffer
size:

cec->rx_msg.msg[cec->rx_msg.len++] = val & 0xFF;

rx_msg.msg[] is a fixed CEC_MAX_MSG_SIZE (16) byte array in struct
cec_msg, and rx_msg.len is only reset on RXACKE/RXOVR or after a
completed message (RXEND). The number of bytes received before RXEND is
decided by the remote CEC device (it sets EOM), not by the driver. A
peer that keeps sending bytes without ending the message drives RXBR
repeatedly, pushing rx_msg.len past 16 and writing peer-controlled bytes
out of bounds into the surrounding memory. This is reachable in normal
operation once the driver has probed and receiving is enabled, from the
IRQ thread, without any local privilege.

The length check in the CEC core runs on the consumer side, after the
byte has been stored, so it does not prevent the overflow. Bound the
index in the driver before the store, as the other platform CEC drivers
already do (e.g. tegra_cec), dropping the excess bytes of an overlong
frame.

Found by static analysis tool CodeQL.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds write leading to memory corruption
Action: Immediate patch
AI Analysis

Impact

The Linux kernel’s stm32 CEC driver appends each received byte to an array that has a fixed size of 16 elements. The driver increments the write index on every receive interrupt without verifying that it remains within the buffer bounds. When a remote peer sendsEC frame, the driver writes past the end of the array and overwrites adjacent memory. This classic buffer‑overflow flaw (CWE‑787) can corrupt kernel data structures, potentially causing a crash, loss of integrity, or, in the worst case, an indeterminate state.

Affected Systems

All Linux kernel distributions that include the stm32 CEC driver before the commit that introduces a bounds check are affected. The bug is present whenever the driver is built and enabled, which is typical on embedded devices that use an STM32 processor with CEC support. Systems that compile this module for any architecture—such as ARM or x86—carry the same risk if they expose the CEC interface.

Risk and Exploitability

The vulnerability scores 8.8 on the CVSS scale and has an EPSS of <1 %. It is not listed in the CISA KEV catalog, indicating no widespread exploitation has been observed to date. The flaw is reachable during normal operation; an attacker only needs the ability to inject CEC packets at the target device. Because the vulnerability is triggered in an interrupt context without privilege checks, any remote peer capable of sending CEC frames can invoke the overflow, potentially leading to denial of service or corrupted system state.

Generated by OpenCVE AI on September 15, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel release that contains the stm32 CEC driver bounds‑check patch committed in the upstream repository.
  • If an updated kernel is not yet available, disable the stm32 CEC driver by blacklisting the module or removing its entry from the device tree to stop the overflow from occurring.
  • Continuously monitor kernel logs for indications of buffer overflow activity and review vendor security advisories for the latest patches.

Generated by OpenCVE AI on September 15, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent out-of-bounds write on RX overflow stm32_rx_done() appends each received CEC byte to rx_msg.msg[] using rx_msg.len as the write index, incrementing it on every RXBR (receive-byte-ready) interrupt without checking it against the buffer size: cec->rx_msg.msg[cec->rx_msg.len++] = val & 0xFF; rx_msg.msg[] is a fixed CEC_MAX_MSG_SIZE (16) byte array in struct cec_msg, and rx_msg.len is only reset on RXACKE/RXOVR or after a completed message (RXEND). The number of bytes received before RXEND is decided by the remote CEC device (it sets EOM), not by the driver. A peer that keeps sending bytes without ending the message drives RXBR repeatedly, pushing rx_msg.len past 16 and writing peer-controlled bytes out of bounds into the surrounding memory. This is reachable in normal operation once the driver has probed and receiving is enabled, from the IRQ thread, without any local privilege. The length check in the CEC core runs on the consumer side, after the byte has been stored, so it does not prevent the overflow. Bound the index in the driver before the store, as the other platform CEC drivers already do (e.g. tegra_cec), dropping the excess bytes of an overlong frame. Found by static analysis tool CodeQL.
Title media: cec: stm32: prevent out-of-bounds write on RX overflow
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:16.023Z

Reserved: 2026-09-11T19:38:34.759Z

Link: CVE-2026-89725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:02.567

Modified: 2026-09-14T13:19:21.730

Link: CVE-2026-89725

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:36Z

Links: CVE-2026-89725 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses