Description
In the Linux kernel, the following vulnerability has been resolved:

media: tda18250: fix possible integer overflow

Integer overflow may occur, when variable exp equals to zero. Result
of shift 1 << (exp - 1) may then leads to undefined behavior.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel crash due to integer overflow leading to undefined behavior
Action: Patch
AI Analysis

Impact

The vulnerability is an integer overflow in the tda18250 media driver module of the Linux kernel. When the variable "exp" equals zero, the expression 1 << (exp - 1) evaluates to an undefined shift, which can corrupt kernel memory or otherwise lead to undefined behavior. An attacker who can influence the "exp" value may exploit this flaw, potentially causing a kernel crash or other undefined behavior. The exact impact is not explicitly stated in the advisory, but the nature of the overflow suggests serious integrity and availability risks at the kernel level.

Affected Systems

The flaw exists in the generic Linux kernel, affecting all releases that include the tda18250 media driver prior to the fix committed in the kernel source. Version ranges are not listed, so any kernel build that contains the vulnerable tda18250 code without the patch is susceptible.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low exploitation likelihood at the time of analysis. The primary attack vector is inferred to be local access to the tda18250 driver, typically from a user or process with permission to interact with the device. A remote exploitation scenario is not suggested by the supplied data.

Generated by OpenCVE AI on September 18, 2026 at 03:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the tda18250 overflow fix.
  • If an immediate kernel update is not possible, disable the tda18250 driver or disconnect the associated hardware to eliminate the vulnerability’s use path.
  • After applying the patch or disabling the driver, monitor the system for abnormal kernel behavior or crashes to verify that the vulnerability has been mitigated.

Generated by OpenCVE AI on September 18, 2026 at 03:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: tda18250: fix possible integer overflow Integer overflow may occur, when variable exp equals to zero. Result of shift 1 << (exp - 1) may then leads to undefined behavior.
Title media: tda18250: fix possible integer overflow
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:43.473Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89876

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.867

Modified: 2026-09-16T11:16:55.867

Link: CVE-2026-89876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound