Heap-based buffer overflow in Linux kernel - CVE-2026-89436
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to write beyond allocated memory.
The vulnerability exists due to a heap-based buffer overflow in the pcc->sinf array in acpi_pcc_retrieve_biosdata() when processing ACPI HKEY.SINF data whose package count equals the allocated array length. A local user can cause the driver to process such data to write beyond allocated memory.