{"id":"CVE-2026-89898","published":"2026-09-16T11:16:58.660","lastModified":"2026-09-16T15:18:16.073","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: extron-da-hd-4k-plus: add sanity check\n\nAdd check to prevent overflowing msg.msg[] in case the incoming data\nis malformed.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/00c13b4ab481a09d915d099815cff1b10926ddd9","tags":[]},{"url":"https://git.kernel.org/stable/c/673611cc2ab9769929644ce879f7ea34932a3011","tags":[]},{"url":"https://git.kernel.org/stable/c/7ad2fec276946a0dedfa54eb26fc38c4fc6a6034","tags":[]},{"url":"https://git.kernel.org/stable/c/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows for potential buffer overflow in the Linux kernel's CEC driver, which could lead to denial of service or potentially more severe consequences if exploited.","exploitability":"Exploitation requires malformed CEC data to be received, making it moderately difficult. The attacker must have the ability to send such data to the affected system.","blast_radius":"If exploited, the impact could range from a denial of service to more severe consequences, depending on the system's configuration and the services running on it.","remediation":"Upgrade to the fixed version 5.15.100 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["buffer-overflow","kernel","linux","cec"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:15:46.290Z"}}