CVE-2026-89897: media: cec: Serialize exclusive follower delivery

Published Sep 16, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

media: cec: Serialize exclusive follower delivery

cecreceivenotify() reads the exclusive follower pointer without the adapter lock. Serialize the no-follower check and message delivery against mode changes and release.

Event History

Sep 16, 2026
CVE Published
via MITRE·10:31 AM
Data Sourced
via MITRE·10:31 AM
Description

Frequently Asked Questions

1

What conditions are required for this issue to occur?

The issue involves concurrent CEC message receipt and changes to, or release of, the exclusive follower configuration. The vulnerable path is cec_receive_notify(), which previously checked and used the exclusive follower pointer without holding the adapter lock.

2

Which systems are exposed?

Systems using the Linux kernel CEC media subsystem are relevant, particularly where exclusive follower delivery is used and its mode can change or be released while CEC messages are delivered.

3

What is the remediation?

Apply a Linux kernel update containing the locking change that serializes the no-follower check and message delivery with exclusive follower mode changes and release. The provided stable kernel references identify commits carrying the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203