PT-2026-93467 · Linux · Linux Kernel
CVE-2026-89826
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
panthor fw read build info() function where bounds checks for firmware build-info are insufficient. The function validates the metadata range using the addition of hdr.meta start and hdr.meta size; since both are u32 fields, an integer wrap can occur, allowing an out-of-bounds range to pass validation. Additionally, the function reads the "git sha: " prefix without verifying if the metadata is sufficiently long, and a meta size of 0 can lead to an underflow of the NULL terminator index.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel