CVE-2026-89730
Received Received - Intake

altera-cvp Out-of-Bounds Read in Linux Kernel

Vulnerability report for CVE-2026-89730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write The trailing byte path in altera_cvp_send_block() dereferences a u32 pointer even when only 1-3 bytes remain in the input buffer. If the buffer ends at a page or scatterlist boundary, this can read past the valid image data and fault. Copy the remaining bytes into a zero-initialized u32 before writing the final word so only valid bytes are read from the input buffer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-03
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
altera cvp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's FPGA driver for Altera CVP devices. It involves an out-of-bounds read when writing trailing bytes of data. The function altera_cvp_send_block() incorrectly reads a 32-bit value even when only 1-3 bytes remain in the input buffer, which can cause a memory access fault if the buffer ends at a page or scatterlist boundary.

Detection Guidance

This vulnerability is specific to the Linux kernel's FPGA altera-cvp driver and involves out-of-bounds memory reads during buffer handling. Detection requires checking kernel logs for errors related to altera-cvp or FPGA operations. Commands like dmesg | grep altera or journalctl -k | grep altera may help identify issues. Ensure your kernel version is updated to a patched release.

Impact Analysis

This vulnerability could lead to system crashes or instability if exploited. It may allow unauthorized memory access, potentially causing denial-of-service conditions or unexpected behavior in systems using Altera CVP FPGA devices.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-level kernel issue related to memory access in FPGA driver code. Compliance impacts would depend on system-specific implementations and data handling practices rather than this specific vulnerability.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for CVE-2026-89730. If immediate patching is not possible, disable the altera-cvp driver if not in use by blacklisting the module or restricting FPGA operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89730. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart