Improper Validation of Array Index in Linux kernel - CVE-2026-89814

 

Improper Validation of Array Index in Linux kernel - CVE-2026-89814

Published: September 17, 2026


Vulnerability identifier: #VU150473
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89814
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of an array index in the amdgpu isolation enforcement and VM flush paths when processing SDMA submissions using rings outside a partition. A local user can submit SDMA work using a ring that is not assigned to a partition to compromise confidentiality, integrity, and availability.


Affected software

Linux kernel

How to mitigate CVE-2026-89814

Install security update from vendor's repository.


External References

Related Security Bulletins