CVE-2026-89890

Source
https://cve.org/CVERecord?id=CVE-2026-89890
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89890.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89890
Downstream
Published
2026-09-16T10:31:53Z
Modified
2026-09-17T03:47:19Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: go7007: defer the ALSA v4l2 put until card release
Details

In the Linux kernel, the following vulnerability has been resolved:

media: go7007: defer the ALSA v4l2 put until card release

go7007_snd_init() already takes a v4l2_device reference for the ALSA side, but go7007_snd_remove() drops it immediately after calling snd_card_free_when_closed().

That is too early when a userspace process still has the capture PCM open. The ALSA card and its PCM callbacks remain alive until the last file is closed, so the release path can still reach struct go7007 through pcm->private_data and call go7007_snd_hw_free() after the V4L2 release path has freed the object.

Move the matching v4l2_device_put() to the ALSA card private_free callback so the existing ALSA reference covers the whole deferred card lifetime.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89890.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d5d3a7cc127d096c22ad63c4ff72970e1beb22ef
Fixed
1c57d1a3396b2d767d58f10dff09bb397586c714
Fixed
9c4f9628b8558c87903492a777834cc5be14ded3
Fixed
b7a0de398ad510426db9c8e96c516ef7abf48b0e
Fixed
1c9fdd9465211432d5c0ff70caaec0be245823d5
Fixed
29fe4d38fb59ec28ca656cb2dabc2b0f78e78980
Fixed
0745a59945d927652d892437f9647ed6e87c0677
Fixed
e6f1a1ac9b8ccabfec548aef0d0d93eaf4dba4f4
Fixed
1bd456afeb8a515137e567967069fce6f8fcd23e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89890.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89890.json"