{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89894","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.773Z","datePublished":"2026-09-16T10:31:56.101Z","dateUpdated":"2026-09-16T14:39:45.161Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:45.161Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: reject geometry changes while the VBI queue is busy\n\nvidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide\ndev->width / dev->norm but only refuse the change when the *video* queue\n(dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry:\ncx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm,\nthe VBI videobuf2 plane is sized from dev->width / dev->norm in\nvbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then\nrecomputes the destination offset from the *live* dev->width and the\nlatched lines_per_field on every URB completion:\n\n\toffset = lines_completed * (dev->width << 1) + ...;\n\tif (dma_q->current_field == 2)\n\t\toffset += dev->width * 2 * dma_q->lines_per_field;\n\tmemcpy(plane + offset, p_buffer, lencopy);\n\nBecause the VBI node shares video_ioctl_ops with the video node, an\napplication can size a small VBI plane (REQBUFS/QBUF with a small width,\nor with the NTSC standard), then enlarge dev->width (or switch dev->norm\nto PAL) through the video node while the VBI stream is running -- the\nchange is allowed because only dev->vidq is checked -- and let the device\ndeliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the\noffset with the larger geometry and memcpy()s past the end of the smaller\nplane that was already allocated, a heap out-of-bounds write whose offset\nis attacker-chosen and whose contents come from the device. The\nper-field guard in cx231xx_copy_vbi_line() does not help: it bounds the\ncopy against the latched lines_per_field, not the plane's real capacity,\nand vb2 does not re-run buf_prepare() for an already prepared buffer.\n\nRefuse the format/standard change when the VBI queue is busy as well, so\nthe geometry cannot change underneath an allocated VBI buffer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The overflow is reached only through local V4L2 ioctls (VIDIOC_S_FMT/VIDIOC_S_STD plus REQBUFS/QBUF/STREAMON) on the cx231xx /dev/videoN and /dev/vbiN nodes. A USB capture stick being present is a hardware precondition; the attacker does not inject USB packets, so the path is Local rather than Physical.\nAC:L - The attacker fully controls the sequence: shrink width via VIDIOC_S_FMT, allocate a small VBI plane, STREAMON, then enlarge width or switch standard on the video node while only vidq was checked. Subsequent URB completions copy field-2 VBI with the new geometry into the old plane with no race or layout outside the attacker's control.\nPR:L - cx231xx_v4l2_open(), vidioc_s_fmt_vid_cap(), and vidioc_s_std() perform no capability checks. Triggering the bug needs only an unprivileged local user who can open the V4L2 nodes, which udev grants via the video group and uaccess/logind (or the Android camera context), not init-namespace root.\nUI:N - The attacking process opens /dev/videoN and /dev/vbiN and issues the ioctl sequence itself. No separate victim action such as plugging in a device, mounting a filesystem, or running a privileged helper is required.\nS:U - The out-of-bounds memcpy corrupts kernel vmalloc memory belonging to the same host kernel. Impact is local privilege-escalation or denial of service within one security authority, not a VM escape, IOMMU bypass, or other cross-boundary effect.\nC:H - cx231xx_do_vbi_copy() memcpy()s past the undersized VBI plane at an attacker-chosen offset derived from the new width and latched lines_per_field. That heap out-of-bounds write can smash adjacent vmalloc objects and is leverageable for a kernel read primitive.\nI:H - The same attacker-chosen-offset heap out-of-bounds write overwrites kernel memory after the VBI buffer on every field-2 URB completion. An out-of-bounds write of this form is sufficient for control-flow hijacking and an arbitrary write primitive.\nA:H - memcpy() past the allocated VBI plane faults on a vmalloc guard page or corrupts adjacent kernel memory, producing a kernel oops or panic from URB completion context and taking down the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/usb/cx231xx/cx231xx-video.c"],"versions":[{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"aa3314506deb9703bcf0e889db08959440228fbf","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"90d50648af36a1fbf5dbc99238de6fd0e58a13e0","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"a5dd3d7fba358ff9486f3f51b2a9038348c0970a","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"1d1079db8d1807e259a1d2679ed314949797aad9","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"7087bef6510c7df5df0b19192633b8ecc0f33a6f","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"a636c72c7f522d984fa498fc0631f33a2d0be3fd","status":"affected","versionType":"git"},{"version":"7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab","lessThan":"627a121c15fe05a541f44d86016294b80bada75d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/usb/cx231xx/cx231xx-video.c"],"versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf"},{"url":"https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0"},{"url":"https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a"},{"url":"https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d"},{"url":"https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9"},{"url":"https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f"},{"url":"https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd"},{"url":"https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d"}],"title":"media: cx231xx: reject geometry changes while the VBI queue is busy","x_generator":{"engine":"bippy-1.2.0"}}}}