SB20260918405 - Integer underflow in Linux kernel hwtracing coresight driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-90274)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger an out-of-bounds memory access.
The vulnerability exists due to an integer underflow in the ETM4x CoreSight trace driver when handling sequencer state transition controls. A local user can configure sequence state controls to trigger an out-of-bounds memory access.
The issue occurs on trace units for which TRCIDR5.NUMSEQSTATE is zero.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1674d9bff8073bdee5dbc200f56fc3caa28d0566
- https://git.kernel.org/stable/c/1ade9a335c69fc735cb7b3f222ed35ab135540fb
- https://git.kernel.org/stable/c/4091f2d5b26d117c992ffcce1a5df425a0daedcd
- https://git.kernel.org/stable/c/4f9a0f548413bf864f609c9f4bc56e3f1b3577d4
- https://git.kernel.org/stable/c/5ac900f73ce1d4d8308f40752b51bc8a02b244d2
- https://git.kernel.org/stable/c/8d669db59f7283b838e029af29da12e505265fae
- https://git.kernel.org/stable/c/be7b2de5b9a96ae68ffa3528e0a40d63e0fd8148