Out-of-bounds write in Linux kernel - CVE-2026-89904

 

Out-of-bounds write in Linux kernel - CVE-2026-89904

Published: September 17, 2026


Vulnerability identifier: #VU150380
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89904
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the acpi_package_ids[] array when processing a PPTT ACPI table on a LoongArch virtual machine. A remote attacker can trigger the array overflow to cause memory corruption.

The issue can occur on LoongArch virtual machines configured with one core per socket.


Affected software

Linux kernel

How to mitigate CVE-2026-89904

Install security update from vendor's repository.


External References

Related Security Bulletins