SB2026091746 - Integer overflow in Linux kernel include asm
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-89911)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service and compromise confidentiality and integrity.
The vulnerability exists due to an integer overflow in the KVM arm64 TLBI range decoder when processing guest TLB invalidation by range operations. A local user can generate a TLB invalidation range that overflows when added to its base address to cause a denial of service and compromise confidentiality and integrity.
Remediation
Install update from vendor's website.