8.4
CVE-2026-90120
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:24
- Zuletzt bearbeitet 18.09.2026 18:17:42
- Erkennungen
irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing In gic_acpi_parse_iaffid() a given MADT GICC entry might not correspond to a logical cpu recognized by the kernel, resulting in the cpu variable initialization to an error value. Currently, the get_logical_index() return value is not checked for failure, which might result in out-of-bounds memory corruption while trying to index a per_cpu variable array. Add a check to evaluate get_logical_index() return value.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
35866efa52feaf48cc54a0745851a555654e1446
Version <
6caeb878f809bdf0aec2fdd96f3d41ef4b69fc69
Status
affected
Version
35866efa52feaf48cc54a0745851a555654e1446
Version <
328affc639ce9873a7a0a3fd6b8339f19767529b
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.0
Status
affected
Version
0
Version <
7.0
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6caeb878f809bdf0aec2fdd96f3d41ef4b69fc69
https://git.kernel.org/stable/c/328affc639ce9873a7a0a3fd6b8339f19767529b