PT-2026-90205 · Linux · Linux

CVE-2026-89489

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
openrisc: fix arbitrary kernel memory access via or1k atomic syscall
sys or1k atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly.
l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29
The pointers are not checked with access ok(). The four memory accesses also have no exception table entries.
A caller passes a kernel address as either pointer, and the syscall reads from and writes to it directly.
This gives an unprivileged process a kernel read/write primitive. It overwrites kernel data such as the sys call table, gaining code execution in kernel context.
Check both pointers before entering the critical section. Add fixups for the four memory accesses so faults on valid but unmapped user addresses return -EFAULT.
[shorne@gmail.com: fix comment style]

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89489

Produtos afetados

Linux