๐Ÿ” CVE Alert

CVE-2026-89489

HIGH 7.8

openrisc: fix arbitrary kernel memory access via or1k_atomic syscall

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly. l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29 The pointers are not checked with access_ok(). The four memory accesses also have no exception table entries. A caller passes a kernel address as either pointer, and the syscall reads from and writes to it directly. This gives an unprivileged process a kernel read/write primitive. It overwrites kernel data such as the sys_call_table, gaining code execution in kernel context. Check both pointers before entering the critical section. Add fixups for the four memory accesses so faults on valid but unmapped user addresses return -EFAULT. [[email protected]: fix comment style]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < bf310718c6fa6adeee06d207a55489546d860e2c 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < 497cba0b02e5555d99fe9ee1dc478af743ab7f7a 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < 1f2e92e499d863f81df1732af59b4a3559969193 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < 574ae2ac2b314aa33498cd2c28add106cbe644f2 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < a520e8cac54fb403f3800125b606f55fcad42cb9 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < d64a75369cd0f2ee79afcc9d9ca34a3890989379 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < b53435c079c78f89f70a62dd5a322cca4e292b34 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a < 78004e9a87f240df03e2f73120d291763c32e0a7
Linux / Linux
3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/bf310718c6fa6adeee06d207a55489546d860e2c git.kernel.org: https://git.kernel.org/stable/c/497cba0b02e5555d99fe9ee1dc478af743ab7f7a git.kernel.org: https://git.kernel.org/stable/c/1f2e92e499d863f81df1732af59b4a3559969193 git.kernel.org: https://git.kernel.org/stable/c/574ae2ac2b314aa33498cd2c28add106cbe644f2 git.kernel.org: https://git.kernel.org/stable/c/a520e8cac54fb403f3800125b606f55fcad42cb9 git.kernel.org: https://git.kernel.org/stable/c/d64a75369cd0f2ee79afcc9d9ca34a3890989379 git.kernel.org: https://git.kernel.org/stable/c/b53435c079c78f89f70a62dd5a322cca4e292b34 git.kernel.org: https://git.kernel.org/stable/c/78004e9a87f240df03e2f73120d291763c32e0a7