SB2026090574 - Exposure of Resource to Wrong Sphere in Linux kernel dts renesas



SB2026090574 - Exposure of Resource to Wrong Sphere in Linux kernel dts renesas

Published: September 5, 2026

Security Bulletin ID SB2026090574
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-80874)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause system instability.

The vulnerability exists due to improper memory reservation in the reserved-memory definitions for DBSC5 DRAM controller inline ECC areas on Renesas Ironhide hardware when the system is under high DRAM utilization. A local user can cause high DRAM utilization to cause system instability.

DRAM regions immediately preceding the inline ECC carveouts are also unprotected by ECC and require reservation.


Remediation

Install update from vendor's website.