Out-of-bounds read in Linux kernel - CVE-2026-89722
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause an out-of-bounds memory read and write unintended values to PCI I/O ports.
The vulnerability exists due to an unconditional 32-bit load in pci_write_legacy_io() when processing one- or two-byte writes to the legacy_io sysfs file. A local privileged user can submit a one- or two-byte write to the legacy_io sysfs file to cause an out-of-bounds memory read and write unintended values to PCI I/O ports.
The legacy_io sysfs file is available only on Alpha and PowerPC systems that define HAVE_PCI_LEGACY.