Answer in brief
CVE-2026-89885 records a Unknown severity vulnerability in media: platform: mtk-mdp3: Fix SCP device refcounting. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=db4d27e6bbbf511f9cdb33f682535a0a3cb7c403 <dce13bd9bade3ecc1acb7579397f24743850997f || >=31ba1a4d7a5d9466f6ef4910a372b8200f8aad19 <252850653569fdb1a259937e02325cf32c8f0970 || >=8f6f3aa21517ef34d50808af0c572e69580dca20 <0259ade4c4ceaf1e184a7c1aea8071ad398f9b6f || >=8f6f3aa21517ef34d50808af0c572e69580dca20 <55793e4665b7f15151e6f5ab51ca980e73abed5d || >=6.12.64 <6.12.110 || >=6.18.4 <6.18.51 | dce13bd9bade3ecc1acb7579397f24743850997f, 252850653569fdb1a259937e02325cf32c8f0970, 0259ade4c4ceaf1e184a7c1aea8071ad398f9b6f, 55793e4665b7f15151e6f5ab51ca980e73abed5d, 6.12.110, 6.18.51 |
| Linux/Linuxgeneric | 6.19 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Fix SCP device refcounting mdp_probe() first tries to get the SCP handle with scp_get(). When that fails, it falls back to looking up the SCP platform device with __get_pdev_by_id() and then reads its driver data. The fallback lookup returns the platform device with a reference, just like scp_get() does. However, the fallback path currently drops that reference immediately after platform_get_drvdata(). The driver later still calls scp_put(mdp->scp) unconditionally from the probe error path and from mdp_video_device_release(), which drops the SCP device reference again. Keep the fallback reference until the existing scp_put() call, so that the fallback path follows the same ownership rules as the scp_get() path.
Quoted source text, attributed separately from HOL analysis.