platform/x86: ISST: Validate logical CPU id and clos id
Summary
| CVE | CVE-2026-89438 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:24 UTC |
| Updated | 2026-09-11 20:19:24 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: ISST: Validate logical CPU id and clos id
Validate max CLOS ID and logical CPU ID for core power feature.
Reject any clos level or logical CPU number greater than the
supported maximum. These are used to calculate MMIO offset. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e c9ee2770eb95ba316a56d776b2b66666b70c194b git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 5b032e1dda486ca41d10536bd195bd8a559af1e2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 82d4afadb02fb4d7d7bb9230900904c10e49ec87 git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 124e2dbabe460c2a6e7440f4ad8af560131295c9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.4 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.4 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.