CVE-2026-89599

Source
https://cve.org/CVERecord?id=CVE-2026-89599
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89599.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89599
Downstream
Published
2026-09-11T19:45:02Z
Modified
2026-09-13T03:47:19Z
Summary
fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
Details

In the Linux kernel, the following vulnerability has been resolved:

fbdev: omapfb: panel-dsi-cm: initialize lock before registering display

dsicm_probe() registers the display before initializing ddata->lock. Once omapdss_register_display() publishes the display, another consumer can reach a dsicm callback that takes this mutex while it is still uninitialized.

Initialize the mutex before registering the display so the published callbacks always see a valid lock.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89599.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f76ee892a99e68b55402b8d4b8aeffcae2aff34d
Fixed
2c3f8c9c995db185284b079f39177e85b2258176
Fixed
76818e81cfcae33b09b739de09162c7d8d89bf0b
Fixed
09db79078f25c048cfb5d7849795c70415ab8574
Fixed
f8e43fe0f22b7137ce456e6fe3581d3098174f74

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89599.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89599.json"