platform/x86: ISST: Validate socket ID in clos_assoc ioctl
Summary
| CVE | CVE-2026-89442 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:24 UTC |
| Updated | 2026-09-11 20:19:24 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: ISST: Validate socket ID in clos_assoc ioctl
isst_if_clos_assoc() validates the user-supplied socket_id with
'socket_id > topology_max_packages()', but isst_common.sst_inst[] is
allocated with topology_max_packages() entries, so the valid index range
is [0, topology_max_packages()). The '>' comparison lets
socket_id == topology_max_packages() pass and index one entry past the
array.
In addition, isst_common.sst_inst[socket_id] is NULL for an in-range
package that has no bound TPMI SST instance, and the pointer is used
without a NULL check. Both the out-of-bounds entry and the NULL pointer
are then dereferenced by map_partition_power_domain_id() and the
following power_domain_info access.
Reject socket_id >= topology_max_packages() and a NULL sst_inst, matching
the checks already performed by get_instance(). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e 207b4dc6eb100141b122b2602504a1429a4b6558 git |
Not specified |
| CNA |
Linux |
Linux |
affected 12a7d2cb811dd8a884dea088a2701fcb8d00136e a89f07db0cb95c54dac4a8406c79a04e44a73c3c git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.4 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.4 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/207b4dc6eb100141b122b2602504a1429a4b6558 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a89f07db0cb95c54dac4a8406c79a04e44a73c3c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.