Answer in brief
CVE-2026-89892 records a Unknown severity vulnerability in media: em28xx: defer audio-only extension registration. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4a089668ef22c295ed4997289cc48446c849249c <0da1e627f4fc9d0e947fdae90913042120878923 || >=4a089668ef22c295ed4997289cc48446c849249c <f8d7e77d9c621b42a191c67a9b37bec23dc1d555 || >=4a089668ef22c295ed4997289cc48446c849249c <1abe9524dec0fd26e9ceb8d586034d6f68dd8273 || >=4a089668ef22c295ed4997289cc48446c849249c <4e11c45dfdc72ab656067b1df8fcebaf52fd4715 || >=4a089668ef22c295ed4997289cc48446c849249c <d06067ee32620f272cfb80c7bc7c572ad4e74724 || >=4a089668ef22c295ed4997289cc48446c849249c <f9322ac9f862961d7f377b87ec26c8565af7e073 || >=4a089668ef22c295ed4997289cc48446c849249c <4666197ca4f7d80cd3b0292054fe45d76be9ba04 || >=4a089668ef22c295ed4997289cc48446c849249c <95f76f51937fdfb0fc1e14cae606b1ef574a56f3 | 0da1e627f4fc9d0e947fdae90913042120878923, f8d7e77d9c621b42a191c67a9b37bec23dc1d555, 1abe9524dec0fd26e9ceb8d586034d6f68dd8273, 4e11c45dfdc72ab656067b1df8fcebaf52fd4715, d06067ee32620f272cfb80c7bc7c572ad4e74724, f9322ac9f862961d7f377b87ec26c8565af7e073, 4666197ca4f7d80cd3b0292054fe45d76be9ba04, 95f76f51937fdfb0fc1e14cae606b1ef574a56f3 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: media: em28xx: defer audio-only extension registration The audio-only path registers extensions while probing the primary device. For a dual-TS board, this happens before dev_next is created. The duplicate device inherits is_audio_only and is then independently inserted into em28xx_devlist. The list is intended to contain only primary devices: extension operations reach the secondary device through dev_next. The independently linked secondary can be freed during disconnect while its list node remains reachable, resulting in a use-after-free. Defer audio-only extension registration to the module-request work item. It runs only after probing has completed construction of the optional secondary device, so only the primary is registered and extension callbacks reach the secondary through dev_next.
Quoted source text, attributed separately from HOL analysis.