CVE-2026-89731
Received Received - Intake

Buffer Overflow in Linux Kernel CXL RAS Module

Vulnerability report for CVE-2026-89731, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-21

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block. The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read. The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability. Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-21
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's CXL/RAS component. It involves an out-of-bounds read in the cxl_rch_get_aer_info() function when copying AER register data. The function reads past the intended AER register block due to a mismatch between the software layout size and the actual physical AER capability size. This can lead to a second out-of-bounds read when processing the header log.

Detection Guidance

This vulnerability is specific to the Linux kernel's CXL/RAS module and requires kernel-level inspection. Check kernel logs for AER-related errors using dmesg | grep -i aer. Verify if your system uses the affected cxl_rch_get_aer_info() function by inspecting kernel module traces.

Impact Analysis

This vulnerability could allow an attacker with local access to trigger memory corruption or read sensitive kernel memory. It may lead to system crashes, privilege escalation, or information disclosure. Systems using affected Linux kernel versions with CXL/RAS functionality are at risk.

Compliance Impact

This vulnerability involves out-of-bounds memory reads in the Linux kernel's CXL/RAS module, which could lead to memory corruption or information disclosure. While not directly tied to GDPR or HIPAA, such vulnerabilities may impact compliance by potentially exposing sensitive data or disrupting system integrity, which are key concerns under these regulations.

Mitigation Strategies

Update your Linux kernel to the latest stable version where this issue is resolved. If immediate patching is not possible, disable the affected CXL/RAS functionality by blacklisting the cxl module or restricting access to AER registers via kernel parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart