Integer overflow in Linux kernel - CVE-2026-89927
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer overflow in the KVM x86 Hyper-V synthetic timer deadline calculation when programming a synthetic timer with a count value close to U64_MAX. A remote attacker can program a synthetic timer with a crafted count value to cause a denial of service.
Affected software
How to mitigate CVE-2026-89927
External References
- https://git.kernel.org/stable/c/0ca49fbd2883cd53d32d85b50feef17fa04d0fbf
- https://git.kernel.org/stable/c/3097582b73a8ed1cd6f6790fa78706f4a79b5a49
- https://git.kernel.org/stable/c/61954727ee08f026f5e1c9ee69e1b404a68f2f7a
- https://git.kernel.org/stable/c/6a8ba9213cce613455b1502ee0fd178656bf617b
- https://git.kernel.org/stable/c/8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8
- https://git.kernel.org/stable/c/8e19ded84336891646b31375720717635f0fdd90
- https://git.kernel.org/stable/c/a4665762388750e08df99baabe5fce2a21d1423e
- https://git.kernel.org/stable/c/bdb732ebee545b7e3bee7060efc754a8d99818b9