---
id: CVE-2026-89884
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

  Add the missing sanity check after looking up the SCP to avoid
  dereferencing a NULL-pointer in case its …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

  Add the missing sanity check after looking up the SCP to avoid
  dereferencing a NULL-pointer in case its …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 61890ccaefaff89f5babd2c8412fd222c3f5fe38 <
    28548387d79d14c975e77787ebd1f051265e1396
  - >-
    Linux >= 61890ccaefaff89f5babd2c8412fd222c3f5fe38 <
    5026f927ef4150ba12da6f1098cf7952d77b14b6
  - >-
    Linux >= 61890ccaefaff89f5babd2c8412fd222c3f5fe38 <
    426ead7eed6d6b3c3f0fe0925c112ef73fc87256
  - >-
    Linux >= 61890ccaefaff89f5babd2c8412fd222c3f5fe38 <
    90368323fb244da0504e3da37a182f8e89bcc3b9
  - Linux 6.1
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T11:16:56.877'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89884'
references:
  - url: 'https://git.kernel.org/stable/c/28548387d79d14c975e77787ebd1f051265e1396'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/426ead7eed6d6b3c3f0fe0925c112ef73fc87256'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5026f927ef4150ba12da6f1098cf7952d77b14b6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/90368323fb244da0504e3da37a182f8e89bcc3b9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.985Z'
epss: 0.00209
epssPercentile: 0.09747
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Add the missing sanity check after looking up the SCP to avoid
dereferencing a NULL-pointer in case its driver has not yet been bound.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
