CVE-2026-89894

Summary

In the Linux kernel, the following vulnerability has been resolved:

media: cx231xx: reject geometry changes while the VBI queue is busy

vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide dev->width / dev->norm but only refuse the change when the video queue (dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry: cx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm, the VBI videobuf2 plane is sized from dev->width / dev->norm in vbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then recomputes the destination offset from the live dev->width and the latched lines_per_field on every URB completion:

offset = lines_completed * (dev->width << 1) + ...;
if (dma_q->current_field == 2)
	offset += dev->width * 2 * dma_q->lines_per_field;
memcpy(plane + offset, p_buffer, lencopy);

Because the VBI node shares video_ioctl_ops with the video node, an application can size a small VBI plane (REQBUFS/QBUF with a small width, or with the NTSC standard), then enlarge dev->width (or switch dev->norm to PAL) through the video node while the VBI stream is running – the change is allowed because only dev->vidq is checked – and let the device deliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the offset with the larger geometry and memcpy()s past the end of the smaller plane that was already allocated, a heap out-of-bounds write whose offset is attacker-chosen and whose contents come from the device. The per-field guard in cx231xx_copy_vbi_line() does not help: it bounds the copy against the latched lines_per_field, not the plane's real capacity, and vb2 does not re-run buf_prepare() for an already prepared buffer.

Refuse the format/standard change when the VBI queue is busy as well, so the geometry cannot change underneath an allocated VBI buffer.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < aa3314506deb9703bcf0e889db08959440228fbfaffected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < 90d50648af36a1fbf5dbc99238de6fd0e58a13e0affected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < a5dd3d7fba358ff9486f3f51b2a9038348c0970aaffected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < 54ac6df8b8d97eddc3ae97fd2045bdedc8541b6daffected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < 1d1079db8d1807e259a1d2679ed314949797aad9affected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < 7087bef6510c7df5df0b19192633b8ecc0f33a6faffected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < a636c72c7f522d984fa498fc0631f33a2d0be3fdaffected
LinuxLinux7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab < 627a121c15fe05a541f44d86016294b80bada75daffected
LinuxLinux5.5affected
LinuxLinux0 < 5.5unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References