Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-89438
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to access unintended MMIO offsets.
The vulnerability exists due to improper validation of CLOS IDs and logical CPU IDs in the ISST core power feature when handling user-supplied CLOS parameter and association commands. A local user can supply out-of-range CLOS IDs or logical CPU IDs to access unintended MMIO offsets.