Junglewise Threat Intelligence

CVE-2026-89725: Linux kernel STM32 CEC driver out-of-bounds write on RX overflow

CVE-2026-89725 · Severity: high · CVSS 8.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The STM32 CEC (Consumer Electronics Control) driver in the Linux kernel fails to validate message length when receiving data over a local network interface, allowing a malicious device to write beyond a 16-byte buffer. An attacker with network access to the CEC bus can crash the system or potentially execute code by sending an oversized message that overwrites adjacent kernel memory.

Technical details

The vulnerability is a classic buffer overflow in the stm32_rx_done() function, which appends incoming CEC bytes to a fixed 16-byte array (rx_msg.msg[CEC_MAX_MSG_SIZE]) without bounds checking. Each received byte triggers a RXBR (receive-byte-ready) interrupt that increments an index counter without verifying it remains within bounds. A malicious CEC peer that sends more than 16 bytes without signaling end-of-message (EOM) can push the index past the buffer, writing attacker-controlled data into adjacent memory. The vulnerability is network-reachable (CEC bus is local but accessible to any device on the bus once the driver probes and receiving is enabled) and requires no authentication. The fix adds a simple bounds check before the array write, dropping excess bytes in overlong frames.

Affected products

  • Linux Linux kernel All versions with STM32 CEC driver (from linux-5.6.y onwards based on patch availability)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89725 published
  • 2026-06-11: patched: Fix committed by Weigang He
  • 2026-09-07: other: Patch merged by Greg Kroah-Hartman

References

Related threats