CVE-2026-89868: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_streaming When stop_streaming is called, an infinite loop may occur in some cases. Add a bounded poll of the queue status: loop until the queues drain, sleeping briefly between polls, and bail out once VPU_DEC_STOP_TIMEOUT elapses.
Affected products
- Linux Linux: from 6.8, before 6.12.112 (fixed in 6.12.112); from 6.13, before 6.18.53 (fixed in 6.18.53); from 6.19, before 7.2.5 (fixed in 7.2.5)
Published 2026-09-16. Last modified 2026-10-03.