CVE-2026-89883

HIGHCVSS 7.8/10

Last modified

CVE-2026-89883 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe failure After rc_register_device() succeeds, later probe failures must undo the registration with rc_unregister_device(). The current error path jumps to the allocation cleanup label and only calls rc_free_device(), leaving the rc device registration and resources created by rc_register_device() behind. Add a registered-device unwind label for the IRQ lookup, IRQ request, and hardware initialization failure paths.

Description

In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe failure After rc_register_device() succeeds, later probe failures must undo the registration with rc_unregister_device(). The current error path jumps to the allocation cleanup label and only calls rc_free_device(), leaving the rc device registration and resources created by rc_register_device() behind. Add a registered-device unwind label for the IRQ lookup, IRQ request, and hardware initialization failure paths. Keep rc_free_device() for failures before rc_register_device() succeeds.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 4655a591478e4b31a3396695a2457daad9d4c899; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 4efd7146dcf959afe64e9c51531cd8f82e60eab6; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 826763adbd8bd3137c5b3756650da473dc6216d5; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 59951b8a87ef4fb4b5b9409f70ba07663681a040; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 5b58d8c206f37525c8217171e1f3e91dd2fa55e5; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 5e6f5bffaa80fc8ecce348ec0e34fed9d843e47e; >= b4e3e59fb59c214c5bcf9d1bf2971f100e0dac4f, < 479aa6fa8c50f1052f1451326ef7d4d586d340c3
LinuxLinux3.17

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89883?
In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe failure After rc_register_device() succeeds, later probe failures must undo the registration with rc_unregister_device(). The current error path jumps to the allocation cleanup label and only calls rc_free_device(), leaving the rc device registration and resources created by rc_register_device() behind. Add a registered-device unwind label for the IRQ lookup, IRQ request, and hardware initialization failure paths. Keep rc_free_device() for failures before rc_register_device() succeeds.
How severe is CVE-2026-89883?
CVE-2026-89883 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-89883?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89883?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST