Integer underflow in Linux kernel - CVE-2026-90274
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger an out-of-bounds memory access.
The vulnerability exists due to an integer underflow in the ETM4x CoreSight trace driver when handling sequencer state transition controls. A local user can configure sequence state controls to trigger an out-of-bounds memory access.
The issue occurs on trace units for which TRCIDR5.NUMSEQSTATE is zero.
Affected software
How to mitigate CVE-2026-90274
External References
- https://git.kernel.org/stable/c/1674d9bff8073bdee5dbc200f56fc3caa28d0566
- https://git.kernel.org/stable/c/1ade9a335c69fc735cb7b3f222ed35ab135540fb
- https://git.kernel.org/stable/c/4091f2d5b26d117c992ffcce1a5df425a0daedcd
- https://git.kernel.org/stable/c/4f9a0f548413bf864f609c9f4bc56e3f1b3577d4
- https://git.kernel.org/stable/c/5ac900f73ce1d4d8308f40752b51bc8a02b244d2
- https://git.kernel.org/stable/c/8d669db59f7283b838e029af29da12e505265fae
- https://git.kernel.org/stable/c/be7b2de5b9a96ae68ffa3528e0a40d63e0fd8148