Impact
A flaw in the Linux media subsystem causes a shared VPU job slot to be leaked when a decoder instance drains at end‑of‑stream. Because the job finishing routine is incorrectly deferred, video processing threads can stall indefinitely, resulting in a DoS that halts GStreamer pipelines and any code that uses the affected drivers. The weakness is a resource‑management defect that can prevent the system from releasing critical kernel resources.
Affected Systems
All Linux kernel builds that include the media:chips-media wave5 driver are affected; the vulnerability is present in kernel releases before the fix for CVE‑2026‑89867.
Risk and Exploitability
The CVSS score for this issue has not been published, but the EPSS score is below 1% and the vulnerability is not listed in CISA KEV. The bug requires interaction with the media stack and can be triggered by local or privileged processes that submit decoding jobs; it does not provide remote code execution or elevated privilege escalation directly. Because the issue causes a resource leak that may lead to system stall, the risk is moderate but low probability of exploitation under current metrics.
OpenCVE Enrichment