Integer overflow in Linux kernel - CVE-2026-89513
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to perform out-of-bounds reads and writes.
The vulnerability exists due to an integer overflow in the RISC-V KVM PMU event information handler when processing an SBI PMU EVENT_GET_INFO request with a guest-controlled event count. A local user can provide a num_events value that causes the shared-memory size calculation to truncate, resulting in an undersized array and out-of-bounds reads and writes.
Exploitation was demonstrated from a nested guest.