SB2026091746 - Integer overflow in Linux kernel include asm



SB2026091746 - Integer overflow in Linux kernel include asm

Published: September 17, 2026

Security Bulletin ID SB2026091746
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Integer overflow (CVE-ID: CVE-2026-89911)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service and compromise confidentiality and integrity.

The vulnerability exists due to an integer overflow in the KVM arm64 TLBI range decoder when processing guest TLB invalidation by range operations. A local user can generate a TLB invalidation range that overflows when added to its base address to cause a denial of service and compromise confidentiality and integrity.


Remediation

Install update from vendor's website.