PT-2026-93588 · Linux · Linux Kernel
CVE-2026-89947
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.0
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 7.0.0-rc5
Description
An out-of-bounds read occurs in the Linux kernel due to a mismatch between the actual number of parents and the hard-coded
num parents field in the gxbb 32k clk sel mux. This issue was triggered when a non-existing clock parent was removed without updating the corresponding count, leading to a global-out-of-bounds access during the execution of the clk register() function. The problem specifically affects the gxbb 32k clk parents variable.Recommendations
Update the Linux kernel to a version where the
num parents field is dynamically calculated using ARRAY SIZE to ensure it aligns with the actual count of clock parents.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel