Off-by-one in Linux kernel - CVE-2026-89751
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect port I/O handling.
The vulnerability exists due to an off-by-one error in handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c when emulating port I/O operations. A local user can perform port I/O operations that invoke the affected handlers to cause incorrect port I/O handling.