SB2026091758 - Out-of-bounds write in Linux kernel loongarch kernel



SB2026091758 - Out-of-bounds write in Linux kernel loongarch kernel

Published: September 17, 2026

Security Bulletin ID SB2026091758
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-89904)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the acpi_package_ids[] array when processing a PPTT ACPI table on a LoongArch virtual machine. A remote attacker can trigger the array overflow to cause memory corruption.

The issue can occur on LoongArch virtual machines configured with one core per socket.


Remediation

Install update from vendor's website.