← All Advisories

CVE-2026-89731

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89731

Key Details

CVECVE-2026-89731
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from

the RCRB MMIO block using a readl() loop bounded by sizeof(struct

aer_capability_regs). This struct is a software layout and its embedded

struct pcie_tlp_log is larger than the on-wire AER capability. As a

result the loop reads past the mapped AER register block.

The over-read also populates the software-only tail fields including

header_log.header_len. An out-of-range header_len passed to

pcie_print_tlp_log() can then loop past the header log buffer and cause

a second out-of-bounds read.

The read was correct when introduced, but struct pcie_tlp_log has since

grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),

so sizeof(struct aer_capability_regs) no longer matches the physical AER

capability.

Bound the read to the physical AER registers, header through the 16 byte

Header Log. Zero the destination first so the software-only fields are

deterministic. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89731
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89731