PT-2026-93588 · Linux · Linux Kernel

CVE-2026-89947

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 7.0.0-rc5
Description An out-of-bounds read occurs in the Linux kernel due to a mismatch between the actual number of parents and the hard-coded num parents field in the gxbb 32k clk sel mux. This issue was triggered when a non-existing clock parent was removed without updating the corresponding count, leading to a global-out-of-bounds access during the execution of the clk register() function. The problem specifically affects the gxbb 32k clk parents variable.
Recommendations Update the Linux kernel to a version where the num parents field is dynamically calculated using ARRAY SIZE to ensure it aligns with the actual count of clock parents.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101472
CVE-2026-89947
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel