Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89731

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read<br /> <br /> cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from<br /> the RCRB MMIO block using a readl() loop bounded by sizeof(struct<br /> aer_capability_regs). This struct is a software layout and its embedded<br /> struct pcie_tlp_log is larger than the on-wire AER capability. As a<br /> result the loop reads past the mapped AER register block.<br /> <br /> The over-read also populates the software-only tail fields including<br /> header_log.header_len. An out-of-range header_len passed to<br /> pcie_print_tlp_log() can then loop past the header log buffer and cause<br /> a second out-of-bounds read.<br /> <br /> The read was correct when introduced, but struct pcie_tlp_log has since<br /> grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),<br /> so sizeof(struct aer_capability_regs) no longer matches the physical AER<br /> capability.<br /> <br /> Bound the read to the physical AER registers, header through the 16 byte<br /> Header Log. Zero the destination first so the software-only fields are<br /> deterministic.