---
cve: "CVE-2026-89943"
severity: "HIGH"
cvss: 8.4
epss: "0.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-16 11:17:03"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T02:58:38+02:00"
---

# CVE-2026-89943

> 8.4 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

ASoC: loongson: Fix error handling in ACPI property parsing

In loongson_card_parse_acpi(), the return value of
device_property_read_string() for the `codec-dai-name` property was
ignored. If the property is missing or invalid, an uninitialized pointer
would be used later, potentially leading to undefined behavior.

Fix this by checking the return value and propagating the error
appropriately.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.110
- Kernel ≥ 6.18.51
- Kernel ≥ 7.2.5

## Referenzen

- <https://git.kernel.org/stable/c/682c123cef455545f48ecbe74b3872fa303bf58f>
- <https://git.kernel.org/stable/c/4e580d84a638f007b5b68d50d7633de502f325e7>
- <https://git.kernel.org/stable/c/bb1602908c67db7197ab001638573262bccc6ca2>
- <https://git.kernel.org/stable/c/0eb0e3c623ac1da8b85d518043fef7660af7805d>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89943) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
