Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-89914
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect sign extension in the decode_range_tlbi() helper when processing range-based TLBI invalidation. A remote attacker can trigger range-based TLBI invalidation to compromise confidentiality, integrity, and availability.