Out-of-bounds write in Linux kernel - CVE-2026-89904
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the acpi_package_ids[] array when processing a PPTT ACPI table on a LoongArch virtual machine. A remote attacker can trigger the array overflow to cause memory corruption.
The issue can occur on LoongArch virtual machines configured with one core per socket.