Out-of-bounds write in Linux kernel - CVE-2026-89907

 

Out-of-bounds write in Linux kernel - CVE-2026-89907

Published: September 17, 2026


Vulnerability identifier: #VU150383
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89907
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to corrupt kernel memory.

The vulnerability exists due to improper input validation in the LoongArch KVM pch_msi_set_irq() function when processing user-supplied MSI data. A local user can supply an MSI data value of 256 or greater through KVM MSI routing or signaling interfaces to corrupt kernel memory.

The DMSINTC path is unaffected.


Affected software

Linux kernel

How to mitigate CVE-2026-89907

Install security update from vendor's repository.


External References

Related Security Bulletins