Integer overflow in Linux kernel - CVE-2026-89826
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to integer overflow and improper bounds checking in panthor_fw_read_build_info() when processing firmware build metadata. A local user can supply a firmware image containing crafted metadata values to disclose sensitive information or cause a denial of service.