CVE-2026-89867

Source
https://cve.org/CVERecord?id=CVE-2026-89867
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89867.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89867
Downstream
Published
2026-09-16T10:31:37Z
Modified
2026-09-18T03:48:34Z
Summary
media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued
Details

In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued

Decoder instances sharing a VPU also share one v4l2_m2m job slot, released when the running context calls v4l2_m2m_job_finish(). While draining, device_run() defers job_finish() once EOS is sent (sent_eos), expecting a later finish_decode() (from a DEC_PIC completion IRQ) to release the slot.

But the m2m core checks job_ready() only when a job is queued, not when it is dispatched. A job queued while draining can run after finish_decode() has already moved the instance to STOP and sent EOS. device_run() then runs in STOP, issues no DEC_PIC, yet still skips job_finish() - so no IRQ, no finish_decode(), and the shared slot is leaked, stalling every instance. With several v4l2h264dec instances in parallel, GStreamer hangs at EOS.

Track whether the run actually queued a DEC_PIC (cmd_issued) and defer job_finish() only then. Otherwise finish the job immediately

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89867.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a176ac5e701f1ba30843c0d7e0663a761bf9a61a
Fixed
63d758d2f9dba836d5ae597d317cde522e817cf9
Fixed
b694ba0a5526a69f78a6924982b1553154ccfd73

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89867.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89867.json"