CVE-2026-89943: Linux

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI property parsing In loongson_card_parse_acpi(), the return value of device_property_read_string() for the `codec-dai-name` property was ignored. If the property is missing or invalid, an uninitialized pointer would be used later, potentially leading to undefined behavior. Fix this by checking the return value and propagating the error appropriately.

Affected products

  • Linux Linux: from 6.12, before 6.12.110 (fixed in 6.12.110); from 6.13, before 6.18.51 (fixed in 6.18.51); from 6.19, before 7.2.5 (fixed in 7.2.5)

Published 2026-09-16. Last modified 2026-09-16.