{"id":"CVE-2026-89899","published":"2026-09-16T11:16:58.767","lastModified":"2026-09-16T15:18:16.183","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cec: disable delayed work before freeing an interrupted transmit\n\ncec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in\nwait_for_completion_killable(). If that wait is interrupted by a signal,\ncancel_delayed_work_sync() can run before the CEC kthread arms the reply\ntimeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts().\nThe work is then armed after the cancel, and the data is freed with its\ndelayed_work still pending:\n\n  ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout\n\nUse disable_delayed_work_sync(): it cancels the work and disables it, so\nthe later schedule_delayed_work() becomes a no-op and the work cannot be\nre-armed. The data is freed right after, so it need not be re-enabled.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0fbd5c2327020858c45b2d1c65775d64cdeca523","tags":[]},{"url":"https://git.kernel.org/stable/c/9a951931d4b4084acd64fa55fc3672a9da45ddf9","tags":[]},{"url":"https://git.kernel.org/stable/c/9c6ceb0949227c1f0cf0e19393daec72d9889871","tags":[]},{"url":"https://git.kernel.org/stable/c/a3adb63b121937b97f7fdc51e96564c7c799538b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}