CVE-2026-89438

Source
https://cve.org/CVERecord?id=CVE-2026-89438
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89438.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89438
Downstream
Published
2026-09-11T19:43:08Z
Modified
2026-09-13T03:47:18Z
Summary
platform/x86: ISST: Validate logical CPU id and clos id
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: ISST: Validate logical CPU id and clos id

Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are used to calculate MMIO offset.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89438.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
12a7d2cb811dd8a884dea088a2701fcb8d00136e
Fixed
c9ee2770eb95ba316a56d776b2b66666b70c194b
Fixed
5b032e1dda486ca41d10536bd195bd8a559af1e2
Fixed
82d4afadb02fb4d7d7bb9230900904c10e49ec87
Fixed
124e2dbabe460c2a6e7440f4ad8af560131295c9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89438.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89438.json"