---
id: CVE-2026-89898
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: cec: extron-da-hd-4k-plus: add sanity check

  Add check to prevent overflowing msg.msg[] in case the incoming data
  is malformed.
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: cec: extron-da-hd-4k-plus: add sanity check

  Add check to prevent overflowing msg.msg[] in case the incoming data
  is malformed.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 056f2821b631df2b94d3b017fd1e1eef918ed98d <
    00c13b4ab481a09d915d099815cff1b10926ddd9
  - >-
    Linux >= 056f2821b631df2b94d3b017fd1e1eef918ed98d <
    673611cc2ab9769929644ce879f7ea34932a3011
  - >-
    Linux >= 056f2821b631df2b94d3b017fd1e1eef918ed98d <
    7ad2fec276946a0dedfa54eb26fc38c4fc6a6034
  - >-
    Linux >= 056f2821b631df2b94d3b017fd1e1eef918ed98d <
    abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3
  - Linux 6.12
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:16.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89898'
references:
  - url: 'https://git.kernel.org/stable/c/00c13b4ab481a09d915d099815cff1b10926ddd9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/673611cc2ab9769929644ce879f7ea34932a3011'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7ad2fec276946a0dedfa54eb26fc38c4fc6a6034'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.979Z'
epss: 0.00379
epssPercentile: 0.29096
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: cec: extron-da-hd-4k-plus: add sanity check

Add check to prevent overflowing msg.msg[] in case the incoming data
is malformed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
