Incorrect Check of Function Return Value in Linux kernel - CVE-2026-89957

 

Incorrect Check of Function Return Value in Linux kernel - CVE-2026-89957

Published: September 17, 2026


Vulnerability identifier: #VU150323
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89957
CWE-ID: CWE-253
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to retain stale hardware access to AP devices removed from the host configuration.

The vulnerability exists due to incorrect handling of the bitmap_andnot() return value in vfio_ap_mdev_hot_unplug_cfg() when the last adapter, domain, or control domain assigned to an mdev is removed. A local user can remove the final assigned AP resource from the host configuration to retain stale hardware access to the unplugged AP devices.


Affected software

Linux kernel

How to mitigate CVE-2026-89957

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins