SB2026090574 - Exposure of Resource to Wrong Sphere in Linux kernel dts renesas
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-80874)
CWE-ID: CWE-668 - Exposure of resource to wrong sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause system instability.
The vulnerability exists due to improper memory reservation in the reserved-memory definitions for DBSC5 DRAM controller inline ECC areas on Renesas Ironhide hardware when the system is under high DRAM utilization. A local user can cause high DRAM utilization to cause system instability.
DRAM regions immediately preceding the inline ECC carveouts are also unprotected by ECC and require reservation.
Remediation
Install update from vendor's website.