CVE-2026-89906
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-89906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Refactor jump offset calculation in tail call
The old macro-based jmp_offset calculation derives the jump distance
from a stale prior-pass code stride, which can lead to wrong branch
offsets and soft lockups under extra JIT passes.
Fix this by calculating the offset directly on the absolute target:
"ctx->offset[insn + 1] - ctx->idx".
To avoid a false 16-bit range check abort during size estimation, add
a "ctx->image == NULL" guard to inject a safe dummy offset.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | cd39d9e6b7e4c58fa77783e7aedf7ada51d02ea3 |
| Linux | Linux | cd39d9e6b7e4c58fa77783e7aedf7ada51d02ea3 |
| Linux | Linux | cd39d9e6b7e4c58fa77783e7aedf7ada51d02ea3 |
| Linux | Linux | 1a782fa32e644aa9fbae6c8488f3e61221ac96e1 |
| Linux | Linux | 17c010fe45def335fe03a0718935416b04c7f349 |
| Linux | Linux | f83d469e16bb1f75991ca67c56786fb2aaa42bea |
| Linux | Linux | f2b5e50cc04d7a049b385bc1c93b9cbf5f10c94f |
| Linux | Linux | 9262e3e04621558e875eb5afb5e726b648cd5949 |
| Linux | Linux | 6.1.149 |
| Linux | Linux | 6.6.103 |
| Linux | Linux | 6.12.43 |
| Linux | Linux | 6.15.11 |
| Linux | Linux | 6.16.2 |
| Linux | Linux | 6.17 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |