CVE-2026-89884

Source
https://cve.org/CVERecord?id=CVE-2026-89884
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89884.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89884
Downstream
Published
2026-09-16T10:31:49Z
Modified
2026-09-17T03:47:19Z
Summary
media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Add the missing sanity check after looking up the SCP to avoid dereferencing a NULL-pointer in case its driver has not yet been bound.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89884.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
61890ccaefaff89f5babd2c8412fd222c3f5fe38
Fixed
28548387d79d14c975e77787ebd1f051265e1396
Fixed
5026f927ef4150ba12da6f1098cf7952d77b14b6
Fixed
426ead7eed6d6b3c3f0fe0925c112ef73fc87256
Fixed
90368323fb244da0504e3da37a182f8e89bcc3b9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89884.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89884.json"