Out-of-bounds read in Linux kernel - CVE-2026-89571
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose kernel memory contents and cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the cxlctl_fw_rpc() CXL fwctl command handler when processing a command whose operation size exceeds its input buffer. A local user can submit a crafted fwctl command with a large operation size to disclose kernel memory contents and cause a denial of service.