CVE-2026-89721

Summary

In the Linux kernel, the following vulnerability has been resolved:

phy: rockchip-samsung-dcphy: fix out-of-range max_register

The PHY register block is 64KB, so with a register stride of 4 the last accessible register sits at offset 0xfffc. max_register names 0x10000, one register past the end of the mapping: dumping the registers through the regmap debugfs interface reads beyond the ioremapped region and oopses on the unmapped page. The oops fires with the regmap lock held, so later PHY operations deadlock.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < 14afe18655c0951f4f85898f761bf92264e65ccdaffected
LinuxLinuxb2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < c1a62f9dcf531d56c56da2e4435386b6d264c69faffected
LinuxLinuxb2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < 4486e75ba647bd8b98fc1f053101b40caceeed4baffected
LinuxLinux6.15affected
LinuxLinux0 < 6.15unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References