CVE-2026-89904
8.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix acpi_package_ids[] array overflow
With LoongArch virt machine, a typical setting is one core per socket, there will max 256 sockets (packages) on one VM. With PPTT acpi table, array acpi_package_ids[] will be overflowed.
Here change the array size of acpi_package_ids[] with the max value of MAX_PACKAGES and KVM_MAX_VCPUS.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f18992be262d6515c94bf4bf6ce7598135076771 < 0195e04b1eec8fb00e2db9c5e55655a3f5e76f60 | affected |
| Linux | Linux | 4427a33faabb4b81511b99dfee18ce0a38b5b5df < d3fd094c13c6d0b74f246461ca4cf427d539c8e8 | affected |
| Linux | Linux | 4e8f58620f6717f72f3d88a2c8f25c0c656d0ba7 < 6311b8c471afa33c18adbe4eb16f862936b71ca3 | affected |
| Linux | Linux | 4e8f58620f6717f72f3d88a2c8f25c0c656d0ba7 < 2a2367d46d7a4ee4122b7a86e57125542dbbe963 | affected |
| Linux | Linux | 496bc868d9066e034787aa14b8ad6c23e77b51ef | affected |
| Linux | Linux | 6.12.101 < 6.12.110 | affected |
| Linux | Linux | 6.18.42 < 6.18.51 | affected |
| Linux | Linux | 7.1.6 < 7.2 | affected |
| Linux | Linux | 7.2 | affected |
| Linux | Linux | 0 < 7.2 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/0195e04b1eec8fb00e2db9c5e55655a3f5e76f60
- https://git.kernel.org/stable/c/d3fd094c13c6d0b74f246461ca4cf427d539c8e8
- https://git.kernel.org/stable/c/6311b8c471afa33c18adbe4eb16f862936b71ca3
- https://git.kernel.org/stable/c/2a2367d46d7a4ee4122b7a86e57125542dbbe963
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.