Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-80874

 

Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-80874

Published: September 5, 2026


Vulnerability identifier: #VU147043
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80874
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause system instability.

The vulnerability exists due to improper memory reservation in the reserved-memory definitions for DBSC5 DRAM controller inline ECC areas on Renesas Ironhide hardware when the system is under high DRAM utilization. A local user can cause high DRAM utilization to cause system instability.

DRAM regions immediately preceding the inline ECC carveouts are also unprotected by ECC and require reservation.


Affected software

Linux kernel

How to mitigate CVE-2026-80874

Install security update from vendor's repository.


External References

Related Security Bulletins