CVE-2026-89884

medium

Description

In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Add the missing sanity check after looking up the SCP to avoid dereferencing a NULL-pointer in case its driver has not yet been bound.

References

https://git.kernel.org/stable/c/90368323fb244da0504e3da37a182f8e89bcc3b9

https://git.kernel.org/stable/c/5026f927ef4150ba12da6f1098cf7952d77b14b6

https://git.kernel.org/stable/c/426ead7eed6d6b3c3f0fe0925c112ef73fc87256

https://git.kernel.org/stable/c/28548387d79d14c975e77787ebd1f051265e1396

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002