CVE-2026-89884 PUBLISHED

media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Assigner: Linux
Reserved: 11.09.2026 Published: 16.09.2026 Updated: 16.09.2026

In the Linux kernel, the following vulnerability has been resolved:

media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Add the missing sanity check after looking up the SCP to avoid dereferencing a NULL-pointer in case its driver has not yet been bound.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 61890ccaefaff89f5babd2c8412fd222c3f5fe38 to 28548387d79d14c975e77787ebd1f051265e1396 (excl.)
  • affected from 61890ccaefaff89f5babd2c8412fd222c3f5fe38 to 5026f927ef4150ba12da6f1098cf7952d77b14b6 (excl.)
  • affected from 61890ccaefaff89f5babd2c8412fd222c3f5fe38 to 426ead7eed6d6b3c3f0fe0925c112ef73fc87256 (excl.)
  • affected from 61890ccaefaff89f5babd2c8412fd222c3f5fe38 to 90368323fb244da0504e3da37a182f8e89bcc3b9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.1 is affected
  • unaffected from 0 to 6.1 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.51 to 6.18.* (incl.)
  • unaffected from 7.2.5 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References