SB2026091758 - Out-of-bounds write in Linux kernel loongarch kernel
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89904)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the acpi_package_ids[] array when processing a PPTT ACPI table on a LoongArch virtual machine. A remote attacker can trigger the array overflow to cause memory corruption.
The issue can occur on LoongArch virtual machines configured with one core per socket.
Remediation
Install update from vendor's website.