{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89883","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.772Z","datePublished":"2026-09-16T10:31:48.378Z","dateUpdated":"2026-09-16T14:39:34.436Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:34.436Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: sunxi-cir: Unregister rc device on probe failure\n\nAfter rc_register_device() succeeds, later probe failures must undo the\nregistration with rc_unregister_device(). The current error path jumps to\nthe allocation cleanup label and only calls rc_free_device(), leaving the\nrc device registration and resources created by rc_register_device()\nbehind.\n\nAdd a registered-device unwind label for the IRQ lookup, IRQ request, and\nhardware initialization failure paths. Keep rc_free_device() for failures\nbefore rc_register_device() succeeds."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in sunxi_ir_probe() of the Allwinner CIR platform driver; after a failed probe the leftover rc-core/lirc/input device is reached by opening local /dev/lirc* or /dev/input/event* nodes, not via network packets, Bluetooth, or IR/USB injection.\nAC:L - After rc_register_device() succeeds, IRQ lookup (including -EPROBE_DEFER), request_irq, or sunxi_ir_hw_init failure calls only rc_free_device(); once the leaked rc/lirc node exists, LIRC_SET_REC_TIMEOUT and similar ioctls deterministically use dangling rc_dev->priv with no attacker-uncontrollable race.\nPR:L - A low-privileged local user who can open the leaked /dev/lirc* or input event node (typical input-group/udev access on Allwinner STBs, tablets, and SBCs) can ioctl the leftover rc device; bind/unbind is CAP_SYS_ADMIN, but the higher-severity scenario is exploiting an already leaked node.\nUI:N - The attacker opens the leftover lirc or input device and issues ioctls themselves; no victim must mount a filesystem, plug a device, or otherwise interact.\nS:U - Use-after-free of the probe-owned sunxi_ir object and leftover rc-core state stays in the host kernel and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Failed probe leaves the rc device registered while devres frees the sunxi_ir object that rc_dev->priv still points at, a slab use-after-free; per kernel CVSS guidance that primitive enables arbitrary kernel read.\nI:H - sunxi_ir_set_timeout() performs CIR MMIO writes through freed ir->base, and leftover s_timeout/ir_raw callbacks can be redirected after heap reuse, yielding arbitrary write and control-flow hijack.\nA:H - Using the leftover lirc/input node dereferences freed sunxi_ir state or writes unmapped CIR MMIO, causing kernel oops/panic; any use-after-free is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/rc/sunxi-cir.c"],"versions":[{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"4655a591478e4b31a3396695a2457daad9d4c899","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"4efd7146dcf959afe64e9c51531cd8f82e60eab6","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"826763adbd8bd3137c5b3756650da473dc6216d5","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"59951b8a87ef4fb4b5b9409f70ba07663681a040","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"5b58d8c206f37525c8217171e1f3e91dd2fa55e5","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"5e6f5bffaa80fc8ecce348ec0e34fed9d843e47e","status":"affected","versionType":"git"},{"version":"b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f","lessThan":"479aa6fa8c50f1052f1451326ef7d4d586d340c3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/rc/sunxi-cir.c"],"versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4655a591478e4b31a3396695a2457daad9d4c899"},{"url":"https://git.kernel.org/stable/c/4efd7146dcf959afe64e9c51531cd8f82e60eab6"},{"url":"https://git.kernel.org/stable/c/826763adbd8bd3137c5b3756650da473dc6216d5"},{"url":"https://git.kernel.org/stable/c/59951b8a87ef4fb4b5b9409f70ba07663681a040"},{"url":"https://git.kernel.org/stable/c/5b58d8c206f37525c8217171e1f3e91dd2fa55e5"},{"url":"https://git.kernel.org/stable/c/5e6f5bffaa80fc8ecce348ec0e34fed9d843e47e"},{"url":"https://git.kernel.org/stable/c/479aa6fa8c50f1052f1451326ef7d4d586d340c3"}],"title":"media: rc: sunxi-cir: Unregister rc device on probe failure","x_generator":{"engine":"bippy-1.2.0"}}}}