CVE-2026-89876

Source
https://cve.org/CVERecord?id=CVE-2026-89876
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89876.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89876
Downstream
Published
2026-09-16T10:31:43Z
Modified
2026-09-18T03:48:33Z
Summary
media: tda18250: fix possible integer overflow
Details

In the Linux kernel, the following vulnerability has been resolved:

media: tda18250: fix possible integer overflow

Integer overflow may occur, when variable exp equals to zero. Result of shift 1 << (exp - 1) may then leads to undefined behavior.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89876.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
148abd3b5b146021a637d36ac5c0ee91cd4ad520
Fixed
cf8e3b3d7d9a6a96f4df6246e2e14b32f58d889e
Fixed
4e21f0e5696d3148b183c7e21dd44f7dec0d07ef
Fixed
3e5568d554c5f6da2cbba45684295927ebefd943
Fixed
593b1172e5d548581dfdb9a63713088f5dfab255
Fixed
0e0fbdb4c9381e2ea647a3fe3bf39bdb02ea5b73
Fixed
7c62bd653563939ff0d0fdfd4b8c73c4f97a1dcc
Fixed
f1ba602afd5ee6609fd71a0d112d18e8447a485f
Fixed
6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89876.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89876.json"