๐Ÿ” CVE Alert

CVE-2026-90191

UNKNOWN 0.0

mailbox: riscv-sbi-mpxy: validate RPMI notification lengths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notification lengths The SBI return value controls how many bytes are copied from shared memory into the RPMI notification buffer. It is not validated against the negotiated shared-memory size before that copy. The event walker also uses a reversed loop condition and can inspect a short event record. Validate the complete notification length before copying it, iterate only while a full event header remains, and stop when a declared event payload extends beyond the copied notification data.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 < cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 < c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76 bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 < 11d5af151bcbe78f5a579e0faecd3be9cea0399a
Linux / Linux
6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b git.kernel.org: https://git.kernel.org/stable/c/c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76 git.kernel.org: https://git.kernel.org/stable/c/11d5af151bcbe78f5a579e0faecd3be9cea0399a