SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89588

HIGH · CVSS 8.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's ACPI subsystem allows for improper length accounting in the handling of ARM hardware errors, potentially leading to out-of-bounds memory access during error data parsing. This flaw could enable attackers to exploit memory corruption, resulting in system instability or unauthorized access to sensitive information. Linux administrators and developers should prioritize addressing this issue to mitigate potential risks associated with system vulnerabilities.

CVE
CVE-2026-89588
Severity
HIGH
CVSS
8.4
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: GHES: fix ARM section length accounting after header In ghes_handle_arm_hw_error(), after skipping the cper_sec_proc_arm header with (err + 1), the remaining length was reduced by sizeof(err) (pointer size) instead of sizeof(*err) (structure size). That overestimates the bytes left for cper_arm_err_info records and can let the parser read past the CPER section when err_info_num is large enough relative to error_data_length. Use sizeof(*err) so the length accounting matches the pointer advance and the earlier sizeof(*err) size check.