CVE-2026-89438

medium

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clos id Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are used to calculate MMIO offset.

References

https://git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b

https://git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87

https://git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2

https://git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-11

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002