Description
In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Add the missing sanity check after looking up the SCP to avoid
dereferencing a NULL-pointer in case its driver has not yet been bound.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel media driver mtk-mdp3 contains a flaw that can cause a NULL pointer dereference when a sensor component (SCP) lookup fails and the driver has not yet been bound. The fault causes a kernel panic, leading to a system reboot or loss of service. This is a classic denial‑of‑service vulnerability.

Affected Systems

All Linux kernel distributions that ship the mtk-mdp3 media platform driver are affected. No specific version range is provided, so the issue may exist in any kernel release that lacks the fix commit.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation in the wild. Based on the description, it is inferred that the attack would require local privileged execution to trigger the path that forces an SCP lookup; remote exploitation is unlikely without additional vulnerabilities. While the impact is limited to a kernel crash, the severity of a denial‑of‑service event remains high for affected hosts.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the mtk-mdp3 NULL dereference fix.
  • If upgrading is not immediately possible, unload or blacklist the mtk-mdp3 driver so it is not loaded during boot.
  • Monitor system logs for SCP lookup failures or kernel panics to verify the mitigation.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Add the missing sanity check after looking up the SCP to avoid dereferencing a NULL-pointer in case its driver has not yet been bound.
Title media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:49.063Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:56.877

Modified: 2026-09-16T11:16:56.877

Link: CVE-2026-89884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses