Integer overflow in Linux kernel - CVE-2026-89911

 

Integer overflow in Linux kernel - CVE-2026-89911

Published: September 17, 2026


Vulnerability identifier: #VU150368
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89911
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service and compromise confidentiality and integrity.

The vulnerability exists due to an integer overflow in the KVM arm64 TLBI range decoder when processing guest TLB invalidation by range operations. A local user can generate a TLB invalidation range that overflows when added to its base address to cause a denial of service and compromise confidentiality and integrity.


Affected software

Linux kernel

How to mitigate CVE-2026-89911

Install security update from vendor's repository.


External References

Related Security Bulletins