CVE-2026-89722
Received Received - Intake

Out-of-Bounds Read in Linux Kernel PCI Legacy I/O

Vulnerability report for CVE-2026-89722, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() pci_write_legacy_io() loads 4 bytes from the kernfs write buffer regardless of how many bytes userspace wrote: if (count != 1 && count != 2 && count != 4) return -EINVAL; return pci_legacy_write(bus, off, *(u32 *)buf, count); kernfs_fop_write_iter() allocates the buffer with kmalloc(len + 1), so a 1-byte write to the legacy_io sysfs file allocates 2 bytes and the unconditional u32 load reads up to 2 bytes past the end of the allocation, which KASAN reports as a slab-out-of-bounds read. Similarly, a 2-byte write overreads by 1 byte. Thus, read only the number of bytes requested using get_unaligned_le16() and get_unaligned_le32() for the 2 and 4 byte cases, interpreting the buffer as little-endian to match the byte ordering of PCI I/O port space. The PowerPC implementation previously compensated for the generic code's native-endian 32-bit load by shifting the value into place for the 1 and 2 byte cases. The shifts were only correct on big-endian kernels. On little-endian PowerPC (POWER8 and later), they extracted the wrong bytes, so a 1-byte write wrote an out-of-bounds byte instead of the requested value. On big-endian, the native load also caused out_le16() and out_le32() to reverse the user's bytes on the wire for 2 and 4 byte writes. The little-endian helpers resolve both issues, so the shifts are removed. No changes are needed for the Alpha platform. The legacy_io file is root-only and exists only on Alpha and PowerPC, the two architectures that define HAVE_PCI_LEGACY.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel where pci_write_legacy_io() reads 4 bytes from a buffer regardless of the actual data size written by userspace. This causes an out-of-bounds read when userspace writes 1 or 2 bytes, as the buffer is only allocated with kmalloc(len + 1). The issue affects PowerPC and Alpha architectures with HAVE_PCI_LEGACY.

Detection Guidance

This vulnerability affects the Linux kernel's PCI/sysfs subsystem, specifically the pci_write_legacy_io() function. Detection requires checking if your system uses a vulnerable kernel version and if the legacy_io sysfs file exists. No direct commands are provided in the context, but you can check your kernel version with 'uname -a' and look for the legacy_io file in /sys/bus/pci/devices/*/legacy_io if you are on Alpha or PowerPC architectures.

Impact Analysis

This vulnerability could allow local attackers with root access to read sensitive kernel memory due to the out-of-bounds read. It may also cause incorrect data to be written for 1 or 2 byte writes on PowerPC systems, potentially leading to system instability or unexpected behavior.

Compliance Impact

This vulnerability involves an out-of-bounds read in the Linux kernel's PCI/sysfs subsystem, which could potentially lead to memory corruption or information disclosure. While not directly tied to GDPR or HIPAA, such vulnerabilities may impact compliance by exposing sensitive data or system integrity issues if exploited. However, the specific impact on compliance depends on the system's configuration and usage.

Mitigation Strategies

Apply the kernel patch that fixes the out-of-bounds read in pci_write_legacy_io(). Since the vulnerability is architecture-specific (Alpha and PowerPC), verify if your system is affected. Update to a patched kernel version if available. Restrict root access to mitigate the risk of exploitation via the legacy_io file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89722. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart