Description
In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: Fix SCP device refcounting

mdp_probe() first tries to get the SCP handle with scp_get(). When that
fails, it falls back to looking up the SCP platform device with
__get_pdev_by_id() and then reads its driver data.

The fallback lookup returns the platform device with a reference, just
like scp_get() does. However, the fallback path currently drops that
reference immediately after platform_get_drvdata(). The driver later
still calls scp_put(mdp->scp) unconditionally from the probe error path
and from mdp_video_device_release(), which drops the SCP device
reference again.

Keep the fallback reference until the existing scp_put() call, so that
the fallback path follows the same ownership rules as the scp_get()
path.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The mtk‑mdp3 media driver in the Linux kernel contains a reference‑counting flaw. When the driver falls back to a platform device lookup after an scp_get() failure, it releases the obtained reference immediately. The driver still later performs an unconditional scp_put(), which underflows the reference count and may free a device still in use. This use‑after‑free can corrupt kernel memory and allows an attacker to execute arbitrary code in kernel mode, resulting in a full system compromise.

Affected Systems

All Linux kernel installations that include the mtk‑mdp3 media driver prior to the upstream commit that fixes the refcounting bug. The vendor product is the Linux kernel; no specific version range is supplied in the CNA data, so any kernel before the patch is potentially affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is reported as < 1 %, signifying a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is local and requires an attacker who can trigger the probe failure path in the driver. This path is not explicitly documented, so the exact conditions for exploitation remain inferred from the description.

Generated by OpenCVE AI on September 18, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the upstream commit correcting the SCP reference‑counting logic.
  • If an immediate kernel upgrade is not possible, backport the patch from the provided git references to the custom kernel source.
  • As a temporary measure, disable the mtk‑mdp3 media driver or block access to the SCP device if it is not essential to system operation, preventing the fault path from being exercised.

Generated by OpenCVE AI on September 18, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Fix SCP device refcounting mdp_probe() first tries to get the SCP handle with scp_get(). When that fails, it falls back to looking up the SCP platform device with __get_pdev_by_id() and then reads its driver data. The fallback lookup returns the platform device with a reference, just like scp_get() does. However, the fallback path currently drops that reference immediately after platform_get_drvdata(). The driver later still calls scp_put(mdp->scp) unconditionally from the probe error path and from mdp_video_device_release(), which drops the SCP device reference again. Keep the fallback reference until the existing scp_put() call, so that the fallback path follows the same ownership rules as the scp_get() path.
Title media: platform: mtk-mdp3: Fix SCP device refcounting
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:35.735Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:56.983

Modified: 2026-09-16T15:18:15.090

Link: CVE-2026-89885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses