{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89443","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.704Z","datePublished":"2026-09-11T19:43:11.407Z","dateUpdated":"2026-09-14T11:59:53.518Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:53.518Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate level in perf mask ioctls\n\nisst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the\nuser-provided level as an index into perf_levels[] via\n_read_pp_level_info() and _read_bf_level_info(), but neither helper\nvalidates it first.\n\nThe adjacent level-info helpers reject levels above max_level before\nreading the same per-level register block. Add the same bounds checks to\nthe mask helpers, and reject disabled SST-PP levels in\nisst_if_get_perf_level_mask() to match isst_if_get_perf_level_info().\n\nThis prevents out-of-bounds reads from the per-level offset table on\ninvalid ioctl input."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local ioctl(ISST_IF_GET_PERF_LEVEL_CPU_MASK or ISST_IF_GET_BASE_FREQ_CPU_MASK) on /dev/isst_interface, dispatched through isst_if_def_ioctl() to the TPMI SST helpers; there is no network, Bluetooth, or physical-device path into these functions.\nAC:L - The attacker fully controls the ioctl argument, including the 8-bit level used as perf_levels[level] with no pre-fix bounds check; the out-of-bounds table read and following MMIO readq() occur deterministically, with no race or attacker-uncontrollable memory layout required.\nPR:L - isst_if_open() and both GET mask ioctls perform no capable() check; CAP_SYS_ADMIN is required only for SST write/set commands, so a local process that can open /dev/isst_interface can reach this read path without init-namespace admin capabilities.\nUI:N - The attacker opens /dev/isst_interface and issues the crafted ioctl from their own process; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The out-of-bounds kernel/MMIO read and any resulting oops stay within the host kernel security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary impact.\nC:H - User-supplied level (0-255) indexes perf_levels[] (at most 8 entries), reading adjacent heap as a signed mmio_offset that is then used in readq(); the 64-bit result is copied to userspace when punit_cpu_map is set, an out-of-bounds read rated High unless strictly a few bytes.\nI:N - Both helpers only issue MMIO readq() and copy_to_user of the resulting mask; there is no writeq, heap write, type confusion, or control-flow hijack primitive on this path.\nA:H - sst_base is a bounded ioremap from devm_ioremap_resource(); a heap-derived mmio_offset can drive readq() outside that mapping and oops, and the perf_levels[] over-read itself can fault on hardened kernels; any kernel crash is High availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c"],"versions":[{"version":"ea009e4769fa3bd05d4c111c3b6865eb3a9be829","lessThan":"beb22ebf76c0415f22d2d0c3f1ff0627e7ae4a68","status":"affected","versionType":"git"},{"version":"ea009e4769fa3bd05d4c111c3b6865eb3a9be829","lessThan":"1a8bab5ceee1a42a78de12d3d69f67516a20588e","status":"affected","versionType":"git"},{"version":"ea009e4769fa3bd05d4c111c3b6865eb3a9be829","lessThan":"1889a9156553f0692acd57caf15e877baace1a01","status":"affected","versionType":"git"},{"version":"ea009e4769fa3bd05d4c111c3b6865eb3a9be829","lessThan":"d19385624bdfb577db9c94bb8879992fd5e17bcd","status":"affected","versionType":"git"},{"version":"ea009e4769fa3bd05d4c111c3b6865eb3a9be829","lessThan":"80e0d353c86a9a168ad6d213f494796294381538","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c"],"versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/beb22ebf76c0415f22d2d0c3f1ff0627e7ae4a68"},{"url":"https://git.kernel.org/stable/c/1a8bab5ceee1a42a78de12d3d69f67516a20588e"},{"url":"https://git.kernel.org/stable/c/1889a9156553f0692acd57caf15e877baace1a01"},{"url":"https://git.kernel.org/stable/c/d19385624bdfb577db9c94bb8879992fd5e17bcd"},{"url":"https://git.kernel.org/stable/c/80e0d353c86a9a168ad6d213f494796294381538"}],"title":"platform/x86: ISST: Validate level in perf mask ioctls","x_generator":{"engine":"bippy-1.2.0"}}}}