---
id: CVE-2026-89876
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: tda18250: fix possible integer overflow

  Integer overflow may occur, when variable exp equals to zero
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: tda18250: fix possible integer overflow

  Integer overflow may occur, when variable exp equals to zero. Result
  of shift 1 << (exp - 1) may then leads to undefined…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    cf8e3b3d7d9a6a96f4df6246e2e14b32f58d889e
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    4e21f0e5696d3148b183c7e21dd44f7dec0d07ef
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    3e5568d554c5f6da2cbba45684295927ebefd943
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    593b1172e5d548581dfdb9a63713088f5dfab255
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    0e0fbdb4c9381e2ea647a3fe3bf39bdb02ea5b73
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    7c62bd653563939ff0d0fdfd4b8c73c4f97a1dcc
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    f1ba602afd5ee6609fd71a0d112d18e8447a485f
  - >-
    Linux >= 148abd3b5b146021a637d36ac5c0ee91cd4ad520 <
    6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4
  - Linux 4.16
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T11:16:55.867'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89876'
references:
  - url: 'https://git.kernel.org/stable/c/0e0fbdb4c9381e2ea647a3fe3bf39bdb02ea5b73'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3e5568d554c5f6da2cbba45684295927ebefd943'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e21f0e5696d3148b183c7e21dd44f7dec0d07ef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/593b1172e5d548581dfdb9a63713088f5dfab255'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7c62bd653563939ff0d0fdfd4b8c73c4f97a1dcc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cf8e3b3d7d9a6a96f4df6246e2e14b32f58d889e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f1ba602afd5ee6609fd71a0d112d18e8447a485f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.986Z'
epss: 0.0022
epssPercentile: 0.11032
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: tda18250: fix possible integer overflow

Integer overflow may occur, when variable exp equals to zero. Result
of shift 1 << (exp - 1) may then leads to undefined behavior.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
