PT-2026-93467 · Linux · Linux Kernel

CVE-2026-89826

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the panthor fw read build info() function where bounds checks for firmware build-info are insufficient. The function validates the metadata range using the addition of hdr.meta start and hdr.meta size; since both are u32 fields, an integer wrap can occur, allowing an out-of-bounds range to pass validation. Additionally, the function reads the "git sha: " prefix without verifying if the metadata is sufficiently long, and a meta size of 0 can lead to an underflow of the NULL terminator index.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89826
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel