CVE-2026-89731

Source
https://cve.org/CVERecord?id=CVE-2026-89731
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89731.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-89731
Downstream
Related
Published
2026-09-11T19:46:41Z
Modified
2026-09-25T18:27:33Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
Details

In the Linux kernel, the following vulnerability has been resolved:

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block.

The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read.

The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability.

Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89731.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Fixed
7f5a2a330dde8e8aa2dd80e1f3e05b6ada049607
Fixed
8bd3523df1319edc61cd391e695c84a4618516df
Fixed
8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced
Fixed
29458e62d0829cbc99435f3e44fd560f9bbf1da7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89731.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89731.json"