CVE-2026-89868

medium

Description

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_streaming When stop_streaming is called, an infinite loop may occur in some cases. Add a bounded poll of the queue status: loop until the queues drain, sleeping briefly between polls, and bail out once VPU_DEC_STOP_TIMEOUT elapses.

References

https://git.kernel.org/stable/c/c343348473e716882249bacf9297d6c363665fd9

https://git.kernel.org/stable/c/c104f37b9f79d6c179c5f1a170d7f1da497ff527

https://git.kernel.org/stable/c/58e185e69a3dbe3494e54aad330f228f0b6645e1

https://git.kernel.org/stable/c/2ae7faed2e60d6d07d9efdd962d20dcb15330ced

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80468

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-10-03

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00209