Description
In the Linux kernel, the following vulnerability has been resolved:

media: cec: extron-da-hd-4k-plus: add sanity check

Add check to prevent overflowing msg.msg[] in case the incoming data
is malformed.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel buffer overflow
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Linux kernel’s media CEC subsystem, within the extron‑da‑hd‑4k‑plus driver. Malformed CEC messages can overflow the msg.msg[] buffer, corrupting kernel memory and potentially allowing an attacker to execute arbitrary code or crash the system.

Affected Systems

The affected product is the Linux kernel. Any distribution or custom kernel build that includes the media CEC subsystem and the extron‑da‑hd‑4k‑plus driver before the patch is vulnerable. No precise version range is given; the flaw exists in the kernel revision containing the unpatched media:c EC code.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity and potentially remote exploitable. EPSS is below 1%, suggesting a low immediate exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via malformed CEC messages sent by an attacker, a deduction made from the description; explicit confirmation is not provided in the advisory.

Generated by OpenCVE AI on September 18, 2026 at 08:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the media cec extron‑da‑hd‑4k‑plus sanity check fix (e.g., apply the latest upstream kernel update containing the relevant commits).
  • If an update is not yet available, disable the CEC subsystem or black‑list the extron driver to reduce exposure.
  • For custom kernels, backport the fix or recompile the kernel with the patch applied.

Generated by OpenCVE AI on September 18, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: cec: extron-da-hd-4k-plus: add sanity check Add check to prevent overflowing msg.msg[] in case the incoming data is malformed.
Title media: cec: extron-da-hd-4k-plus: add sanity check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:47.656Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:58.660

Modified: 2026-09-16T15:18:16.073

Link: CVE-2026-89898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer