CVE-2026-89904

high

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix acpi_package_ids[] array overflow With LoongArch virt machine, a typical setting is one core per socket, there will max 256 sockets (packages) on one VM. With PPTT acpi table, array acpi_package_ids[] will be overflowed. Here change the array size of acpi_package_ids[] with the max value of MAX_PACKAGES and KVM_MAX_VCPUS.

References

https://git.kernel.org/stable/c/d3fd094c13c6d0b74f246461ca4cf427d539c8e8

https://git.kernel.org/stable/c/6311b8c471afa33c18adbe4eb16f862936b71ca3

https://git.kernel.org/stable/c/2a2367d46d7a4ee4122b7a86e57125542dbbe963

https://git.kernel.org/stable/c/0195e04b1eec8fb00e2db9c5e55655a3f5e76f60

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.4

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0018