SB2026091761 - Out-of-bounds write in Linux kernel kvm intc
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89907)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt kernel memory.
The vulnerability exists due to improper input validation in the LoongArch KVM pch_msi_set_irq() function when processing user-supplied MSI data. A local user can supply an MSI data value of 256 or greater through KVM MSI routing or signaling interfaces to corrupt kernel memory.
The DMSINTC path is unaffected.
Remediation
Install update from vendor's website.