{"id":"CVE-2026-89899","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89899","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: disable delayed work before freeing an interrupted transmit\n\ncec_transmit_msg_fh() drops adap->lock…","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: disable delayed work before freeing an interrupted transmit\n\ncec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in\nwait_for_completion_killable(). If that wait is interrupted by a signal,\ncancel_delayed_work_sync() can run before the CEC kthread arms the reply\ntimeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts().\nThe work is then armed after the cancel, and the data is freed with its\ndelayed_work still pending:\n\n  ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout\n\nUse disable_delayed_work_sync(): it cancels the work and disables it, so\nthe later schedule_delayed_work() becomes a no-op and the work cannot be\nre-armed. The data is freed right after, so it need not be re-enabled.","published":"2026-09-16T11:16:58.767","modified":"2026-09-16T11:16:58.767","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0fbd5c2327020858c45b2d1c65775d64cdeca523"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a951931d4b4084acd64fa55fc3672a9da45ddf9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9c6ceb0949227c1f0cf0e19393daec72d9889871"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a3adb63b121937b97f7fdc51e96564c7c799538b"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T11:16:58.767"}}