๐Ÿ” CVE Alert

CVE-2026-89442

HIGH 7.8

platform/x86: ISST: Validate socket ID in clos_assoc ioctl

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with topology_max_packages() entries, so the valid index range is [0, topology_max_packages()). The '>' comparison lets socket_id == topology_max_packages() pass and index one entry past the array. In addition, isst_common.sst_inst[socket_id] is NULL for an in-range package that has no bound TPMI SST instance, and the pointer is used without a NULL check. Both the out-of-bounds entry and the NULL pointer are then dereferenced by map_partition_power_domain_id() and the following power_domain_info access. Reject socket_id >= topology_max_packages() and a NULL sst_inst, matching the checks already performed by get_instance().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
12a7d2cb811dd8a884dea088a2701fcb8d00136e < c847ea4851ecfa3462cc711ded2c3c3dd8d08ab8 12a7d2cb811dd8a884dea088a2701fcb8d00136e < 0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 12a7d2cb811dd8a884dea088a2701fcb8d00136e < 82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca 12a7d2cb811dd8a884dea088a2701fcb8d00136e < 207b4dc6eb100141b122b2602504a1429a4b6558 12a7d2cb811dd8a884dea088a2701fcb8d00136e < a89f07db0cb95c54dac4a8406c79a04e44a73c3c
Linux / Linux
6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c847ea4851ecfa3462cc711ded2c3c3dd8d08ab8 git.kernel.org: https://git.kernel.org/stable/c/0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 git.kernel.org: https://git.kernel.org/stable/c/82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca git.kernel.org: https://git.kernel.org/stable/c/207b4dc6eb100141b122b2602504a1429a4b6558 git.kernel.org: https://git.kernel.org/stable/c/a89f07db0cb95c54dac4a8406c79a04e44a73c3c