CVE-2026-89721
Received Received - Intake

Rockchip Samsung DCphy Register Out-of-Bounds Access

Vulnerability report for CVE-2026-89721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: phy: rockchip-samsung-dcphy: fix out-of-range max_register The PHY register block is 64KB, so with a register stride of 4 the last accessible register sits at offset 0xfffc. max_register names 0x10000, one register past the end of the mapping: dumping the registers through the regmap debugfs interface reads beyond the ioremapped region and oopses on the unmapped page. The oops fires with the regmap lock held, so later PHY operations deadlock.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a misconfiguration in the Rockchip Samsung DCPHY driver. The issue is that the maximum register value is set one register past the actual end of the accessible memory region. This causes the regmap debugfs interface to read beyond the mapped memory, leading to a system crash (oops) when accessing unmapped memory. The crash occurs while holding a lock, which can cause subsequent operations to deadlock.

Detection Guidance

This vulnerability is specific to the Linux kernel's phy: rockchip-samsung-dcphy driver and may not have direct network detection methods. Check kernel logs for oops or deadlock errors related to PHY operations. Use commands like 'dmesg | grep -i oops' or 'journalctl -k | grep -i deadlock' to identify issues.

Impact Analysis

If exploited, this vulnerability could cause your Linux system to crash or become unresponsive due to a kernel oops. It may also lead to a system deadlock, where processes hang indefinitely, requiring a reboot to recover. Systems using the affected PHY driver are at risk of instability or denial of service.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a low-level kernel issue involving a PHY register block out-of-range access. It causes a system crash and potential deadlock but does not involve data exposure or privacy violations.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for this vulnerability. Monitor kernel updates from your distribution and apply them promptly. If immediate patching is not possible, consider disabling the affected PHY driver if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart