Configuration in Linux kernel - CVE-2026-89448

 

Configuration in Linux kernel - CVE-2026-89448

Published: September 12, 2026


Vulnerability identifier: #VU149359
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89448
CWE-ID: CWE-16
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to cause access control services to remain disabled while the IOMMU is forced on.

The vulnerability exists due to improper configuration handling in detect_intel_iommu() when tboot forces the IOMMU on after ACS was not requested. A local privileged user can configure the system to disable ACS to cause access control services to remain disabled while the IOMMU is forced on.


Affected software

Linux kernel

How to mitigate CVE-2026-89448

Install security update from vendor's repository.


External References

Related Security Bulletins