CVE-2026-89897
HIGH
Published Sep 16, 2026
Modified Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: media: cec: Serialize exclusive follower delivery cec_receive_notify() reads the exclusive follower pointer without the adapter lock. Serialize the no-follower check and message delivery against mode changes and release.
Is your site exposed to CVE-2026-89897?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
7.5
HIGH
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Other References
https://git.kernel.org/stable/c/1924d0788caa6c66fd320dd4704fae99487fd2c7
https://git.kernel.org/stable/c/271e57a936dcdbaecb4b1bd005d9a285bbe60ab4
https://git.kernel.org/stable/c/4b532b271c91790b7ab661cd488a7ad36f5c4f6b
https://git.kernel.org/stable/c/5c62095acc2a952099688774513c4a637bcdb2b5
https://git.kernel.org/stable/c/ae614f48712156fb0f55b207338d48d422c58bc0
https://git.kernel.org/stable/c/cac577854826950dda4d53569728b1da6c1425d5
https://git.kernel.org/stable/c/df941e6851da17fc53c7f6af2bdcc7383d17babc
https://git.kernel.org/stable/c/efc829b4b937f98c4467bffe9243f756b7cfbf7f
Frequently Asked Questions
What is CVE-2026-89897? +
In the Linux kernel, the following vulnerability has been resolved:
media: cec: Serialize exclusive follower delivery
cec_receive_notify() reads the exclusive follower pointer without the
adapter lock. Serialize the no-follower check and message delivery
against mode changes and release. It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2026-89897? +
CVE-2026-89897 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
How do I check if I'm vulnerable to CVE-2026-89897? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.