Description
In the Linux kernel, the following vulnerability has been resolved:

media: ti: vpe: quiesce overflow recovery before freeing streams

The VIP overflow recovery worker is armed from the hardirq handler when a
FIFO overflow is detected, and the list-complete path looks the stream up
through the VPDMA list private pointer. Both keep touching stream, port
and device state; the recovery worker also resets the parser and VPDMA,
repopulates the descriptor list, and re-enables the per-list IRQs.

vip_stop_streaming() masks and clears the per-list IRQs, but it neither
synchronizes the hardirq handler nor disables recovery_work. An overflow
IRQ that has already queued recovery_work, or a list-complete IRQ in
flight when the stream is torn down, can therefore still dereference the
stream after its resources are released: the descriptor list is freed by
vip_release_stream() on file release, and the stream itself by
free_stream() on unbind/remove.

Drain the recovery worker and the IRQ handler at both teardown points
through a shared vip_quiesce_stream() helper, before any stream-owned
resource is released. disable_work_sync() cancels pending recovery_work,
drains a running instance, and raises its disable depth, so a subsequent
schedule_work() issued by a racing IRQ handler is rejected at the
workqueue scheduler: recovery_work cannot be requeued after
disable_work_sync() takes effect. The worker may still re-enable the
per-list IRQs before disable_work_sync() returns; disable_irqs() then
masks those sources and synchronize_irq() waits for any in-flight handler
that still dereferences stream state. In vip_stop_streaming() the helper
runs before the parser is stopped, since a worker drained by
disable_work_sync() may re-enable the parser before exiting and would
otherwise undo the stop. recovery_work is created disabled and enabled in
vip_start_streaming() before IRQs, pairing the enable with the teardown
disable across the streaming lifecycle.

This issue was found by an in-house static analysis tool and confirmed
by manual code review.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free that may lead to memory corruption or execution of arbitrary code within the Linux kernel
Action: Immediate Patch
AI Analysis

Impact

A race condition between the hardirq handler and a recovery worker in the Media TI VPE driver allows the worker to dereference a stream whose resources have already been released. The stream descriptor list and stream data structures are freed during stream teardown, but a queued recovery_work may still execute and access those freed pointers, causing a Use‑After‑Free. Such memory corruption within the kernel can be leveraged to modify kernel data or execute arbitrary code with kernel privileges.

Affected Systems

The flaw exists in the Linux kernel’s Media TI VPE driver – all kernel versions prior to the patch that implements the quiesce logic are affected. Any machine that loads this kernel and uses a TI VPE-compatible video processing engine is susceptible; the exact kernel version is not listed but the issue was fixed in the upstream kernel repository in the patch associated with this CVE.

Risk and Exploitability

With a CVSS score of 7.8, the vulnerability is rated high severity. The EPSS score of <1% indicates low predicted exploitation probability, and the flaw is not currently cataloged in CISA’s KEV list. However, exploitation requires an attacker who can trigger a FIFO overflow on the VPE device and coordinate a race with the IRQ handler, meaning local or privileged access to the device driver is typically needed. If achieved, the use‑after‑free could allow the attacker to corrupt kernel memory and potentially gain root or privilege escalation on the affected host.

Generated by OpenCVE AI on September 18, 2026 at 03:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that implements the vip_quiesce_stream helper to properly drain recovery work and IRQs before freeing stream resources
  • If an upgrade is not immediately possible, temporarily disable the VPE hardware or remove the driver so that no streams are processed while the device remains active
  • Verify that no user‑space applications maintain open file descriptors to VPE streams; close them before rebooting or installing the patch
  • After the kernel update, audit the system for any stray references to the VPE driver and confirm that the vulnerability is fully remediated

Generated by OpenCVE AI on September 18, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: quiesce overflow recovery before freeing streams The VIP overflow recovery worker is armed from the hardirq handler when a FIFO overflow is detected, and the list-complete path looks the stream up through the VPDMA list private pointer. Both keep touching stream, port and device state; the recovery worker also resets the parser and VPDMA, repopulates the descriptor list, and re-enables the per-list IRQs. vip_stop_streaming() masks and clears the per-list IRQs, but it neither synchronizes the hardirq handler nor disables recovery_work. An overflow IRQ that has already queued recovery_work, or a list-complete IRQ in flight when the stream is torn down, can therefore still dereference the stream after its resources are released: the descriptor list is freed by vip_release_stream() on file release, and the stream itself by free_stream() on unbind/remove. Drain the recovery worker and the IRQ handler at both teardown points through a shared vip_quiesce_stream() helper, before any stream-owned resource is released. disable_work_sync() cancels pending recovery_work, drains a running instance, and raises its disable depth, so a subsequent schedule_work() issued by a racing IRQ handler is rejected at the workqueue scheduler: recovery_work cannot be requeued after disable_work_sync() takes effect. The worker may still re-enable the per-list IRQs before disable_work_sync() returns; disable_irqs() then masks those sources and synchronize_irq() waits for any in-flight handler that still dereferences stream state. In vip_stop_streaming() the helper runs before the parser is stopped, since a worker drained by disable_work_sync() may re-enable the parser before exiting and would otherwise undo the stop. recovery_work is created disabled and enabled in vip_start_streaming() before IRQs, pairing the enable with the teardown disable across the streaming lifecycle. This issue was found by an in-house static analysis tool and confirmed by manual code review.
Title media: ti: vpe: quiesce overflow recovery before freeing streams
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:29.374Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89875

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.757

Modified: 2026-09-16T15:18:14.437

Link: CVE-2026-89875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses