---
id: CVE-2026-89899
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: cec: disable delayed work before freeing an interrupted transmit

  cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in
  wait_for_completion_k…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: cec: disable delayed work before freeing an interrupted transmit

  cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in
  wait_for_completion_k…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 490d84f6d73c12f4204241cff8651eed60aae914 <
    9a951931d4b4084acd64fa55fc3672a9da45ddf9
  - >-
    Linux >= 490d84f6d73c12f4204241cff8651eed60aae914 <
    a3adb63b121937b97f7fdc51e96564c7c799538b
  - >-
    Linux >= 490d84f6d73c12f4204241cff8651eed60aae914 <
    9c6ceb0949227c1f0cf0e19393daec72d9889871
  - >-
    Linux >= 490d84f6d73c12f4204241cff8651eed60aae914 <
    0fbd5c2327020858c45b2d1c65775d64cdeca523
  - Linux e448dfd6d3ec944411f6575bc24e4f8baa1e297f
  - Linux 2781b86d7e45de09befa5ace296b66787146561f
  - Linux >= 4.18.19 < 4.19
  - Linux >= 4.19.2 < 4.20
  - Linux 4.20
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:16.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89899'
references:
  - url: 'https://git.kernel.org/stable/c/0fbd5c2327020858c45b2d1c65775d64cdeca523'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9a951931d4b4084acd64fa55fc3672a9da45ddf9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9c6ceb0949227c1f0cf0e19393daec72d9889871'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a3adb63b121937b97f7fdc51e96564c7c799538b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.979Z'
epss: 0.00175
epssPercentile: 0.06147
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: cec: disable delayed work before freeing an interrupted transmit

cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in
wait_for_completion_killable(). If that wait is interrupted by a signal,
cancel_delayed_work_sync() can run before the CEC kthread arms the reply
timeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts().
The work is then armed after the cancel, and the data is freed with its
delayed_work still pending:

  ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout

Use disable_delayed_work_sync(): it cancels the work and disables it, so
the later schedule_delayed_work() becomes a no-op and the work cannot be
re-armed. The data is freed right after, so it need not be re-enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
