CVE-2026-89731

Source
https://cve.org/CVERecord?id=CVE-2026-89731
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89731.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89731
Downstream
Published
2026-09-11T19:46:41Z
Modified
2026-09-15T03:31:00Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
Details

In the Linux kernel, the following vulnerability has been resolved:

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block.

The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read.

The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability.

Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89731.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Fixed
8bd3523df1319edc61cd391e695c84a4618516df
Fixed
8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced
Fixed
29458e62d0829cbc99435f3e44fd560f9bbf1da7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89731.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89731.json"