Memory corruption in Linux kernel - CVE-2026-90120
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause out-of-bounds memory corruption.
The vulnerability exists due to improper validation of the get_logical_index() return value in gic_acpi_parse_iaffid() when parsing MADT GICC entries. A local user can trigger parsing of a MADT GICC entry that does not correspond to a logical CPU recognized by the kernel to cause out-of-bounds memory corruption.