PT-2026-93548 · Linux · Linux Kernel
CVE-2026-89907
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
In the LoongArch architecture, the KVM component fails to validate MSI (Message Signaled Interrupts) data before routing it to the EIOINTC. The function
pch msi set irq() passes e->msi.data directly to eiointc set irq() as the interrupt number. Because this data originates from userspace via KVM IRQ ROUTING MSI (set with KVM SET GSI ROUTING) or KVM SIGNAL MSI and is not checked against EIOINTC IRQS, a value of 256 or greater can be provided. This leads to out-of-bounds memory access when eiointc set irq() uses the value on the 256-bit isr bitmap and eiointc update irq() indexes sw coremap[] and per-cpu coreisr/sw coreisr bitmaps. Consequently, any process with a VM file descriptor can corrupt kernel memory beyond the loongarch eiointc allocation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel