8.4

CVE-2026-89885

media: platform: mtk-mdp3: Fix SCP device refcounting

In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: Fix SCP device refcounting

mdp_probe() first tries to get the SCP handle with scp_get(). When that
fails, it falls back to looking up the SCP platform device with
__get_pdev_by_id() and then reads its driver data.

The fallback lookup returns the platform device with a reference, just
like scp_get() does. However, the fallback path currently drops that
reference immediately after platform_get_drvdata(). The driver later
still calls scp_put(mdp->scp) unconditionally from the probe error path
and from mdp_video_device_release(), which drops the SCP device
reference again.

Keep the fallback reference until the existing scp_put() call, so that
the fallback path follows the same ownership rules as the scp_get()
path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version db4d27e6bbbf511f9cdb33f682535a0a3cb7c403
Version < dce13bd9bade3ecc1acb7579397f24743850997f
Status affected
Version 31ba1a4d7a5d9466f6ef4910a372b8200f8aad19
Version < 252850653569fdb1a259937e02325cf32c8f0970
Status affected
Version 8f6f3aa21517ef34d50808af0c572e69580dca20
Version < 0259ade4c4ceaf1e184a7c1aea8071ad398f9b6f
Status affected
Version 8f6f3aa21517ef34d50808af0c572e69580dca20
Version < 55793e4665b7f15151e6f5ab51ca980e73abed5d
Status affected
Version 6.12.64
Version < 6.12.110
Status affected
Version 6.18.4
Version < 6.18.51
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.19
Status affected
Version 0
Version < 6.19
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/dce13bd9bade3ecc1acb7579397f24743850997f
https://git.kernel.org/stable/c/252850653569fdb1a259937e02325cf32c8f0970
https://git.kernel.org/stable/c/0259ade4c4ceaf1e184a7c1aea8071ad398f9b6f
https://git.kernel.org/stable/c/55793e4665b7f15151e6f5ab51ca980e73abed5d