Description
In the Linux kernel, the following vulnerability has been resolved:

media: cec: disable delayed work before freeing an interrupted transmit

cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in
wait_for_completion_killable(). If that wait is interrupted by a signal,
cancel_delayed_work_sync() can run before the CEC kthread arms the reply
timeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts().
The work is then armed after the cancel, and the data is freed with its
delayed_work still pending:

ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout

Use disable_delayed_work_sync(): it cancels the work and disables it, so
the later schedule_delayed_work() becomes a no-op and the work cannot be
re-armed. The data is freed right after, so it need not be re-enabled.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to memory corruption or crash
Action: Update Kernel
AI Analysis

Impact

The vulnerability lies in the Linux kernel's CEC (Consumer Electronics Control) driver. When a transmit operation is interrupted by a signal, the driver may cancel a pending delayed work item before scheduling the next work. The code then frees the data structure while a delayed work reference still points to it, creating a use‑after‑free situation that can crash the kernel or corrupt memory, enabling denial of service.

Affected Systems

Affected systems are any machines running a Linux kernel that includes the CEC driver. The CNA lists the vendor/product as Linux:Linux for all kernel versions, and no specific affected version range is provided. Administrators should consider all current kernel releases that ship the CEC module until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw. The EPSS score is less than 1 % suggesting a low probability of exploitation in the wild at this moment, and it is not listed in CISA's KEV catalog. Nonetheless, the bug allows memory corruption that could be triggered by a malicious process or system error, so mitigation with a kernel update is recommended.

Generated by OpenCVE AI on September 18, 2026 at 03:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fixed CEC driver code.
  • If the system does not rely on CEC functionality, disable or remove the CEC driver from the kernel configuration or module list to eliminate the code path.
  • Apply a system reboot after the kernel update or driver removal to ensure the changes take effect and to clear any lingering references.

Generated by OpenCVE AI on September 18, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: cec: disable delayed work before freeing an interrupted transmit cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in wait_for_completion_killable(). If that wait is interrupted by a signal, cancel_delayed_work_sync() can run before the CEC kthread arms the reply timeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts(). The work is then armed after the cancel, and the data is freed with its delayed_work still pending: ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout Use disable_delayed_work_sync(): it cancels the work and disables it, so the later schedule_delayed_work() becomes a no-op and the work cannot be re-armed. The data is freed right after, so it need not be re-enabled.
Title media: cec: disable delayed work before freeing an interrupted transmit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:48.953Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:58.767

Modified: 2026-09-16T15:18:16.183

Link: CVE-2026-89899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses