{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89570","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.726Z","datePublished":"2026-09-11T19:44:39.584Z","dateUpdated":"2026-09-13T06:31:07.784Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:07.784Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/mce: Make the MCE notifier per-region\n\nFlavien Solt reported lifetime issues with the CXL MCE notifier, which\ncan lead to NULL dereferences and use-after-free in the MCE handler.\nThe notifier was registered per memory device and stored in 'struct\ncxl_memdev_state', even though it only needs the region state (the\nregion's SPA range and its extended linear cache size).\n\nInstead of keeping the memory device and endpoint alive, the correct fix\nis to move the notifier into 'struct cxl_region' and register it from\ncxl_region_probe() as it should be a per-region notifier. Setup the\nregistration to only happen for regions that have an extended linear\ncache as that is the only current usage.\n\nRemove cxl_port_get_spa_cache_alias() as it is now dead code.\n\n[ dj: Update dev_warn() when notifier fails due to kconfig. (Ben) ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - cxl_handle_mce() is invoked from the host x86 MCE decode chain (mce_gen_pool_process() workqueue) after a local machine check; it is not reached from a network protocol, Bluetooth/WiFi, or USB handler. Local access to a CXL Type-3 host is the applicable vector (higher severity than Physical).\nAC:L - The notifier is registered on the PCI device before cxlds->cxlmd is set and while cxlmd->endpoint is ERR_PTR(-ENXIO); cxl_memdev_unregister() never NULLs cxlmd, so probe/AER/unbind leaves a dangling pointer while the notifier stays registered. Any later MCE with a usable address hits the UAF/NULL deref deterministically; EINJ/mce-inject also make the trigger attacker-controlled.\nPR:L - cxl_handle_mce() has no capability check; cxl_pci probe installs the notifier automatically. CXL Type-3 capacity is ordinary System RAM any unprivileged local user can allocate, and async probe, cxl_mem not-yet-bound (ERR_PTR endpoint), or AER-driven detach create the bad lifetime state without init-namespace root, matching CVE-2024-26762.\nUI:N - MCE decode and CXL probe/unbind/AER recovery run in kernel workqueues with no victim mount, file open, or other interactive action; the attacker (or automatic error handling) drives the path themselves.\nS:U - The NULL dereference and use-after-free corrupt host kernel CXL/MCE state in the same OS security authority. This is standard kernel memory corruption/privilege escalation, not a KVM/IOMMU/sandbox boundary crossing.\nC:H - The handler dereferences mds->cxlds.cxlmd and cxlmd->endpoint (and walks endpoint->regions) after those objects can be freed, a use-after-free that can be reclaimed to expose kernel memory. CVSS kernel guidance treats UAF as High confidentiality impact.\nI:H - The same UAF is groomable for an arbitrary write. The callback also computes spa_alias from the dangling objects and calls memory_failure()/set_mce_nospec() on that PFN, so a sprayed cxl_memdev/region can offline attacker-chosen pages and hijack control flow.\nA:H - NULL deref of cxlmd, walking an ERR_PTR endpoint, and UAF of freed memdev/port/region objects cause a kernel oops/panic in the MCE workqueue; UAFs also crash even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/mbox.c","drivers/cxl/core/mce.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h","drivers/cxl/cxlmem.h"],"versions":[{"version":"516e5bd0b6bf4ae1ad072df637b428a737c3c870","lessThan":"5563db13c9528a56c7161260ec75ec8690dc5608","status":"affected","versionType":"git"},{"version":"516e5bd0b6bf4ae1ad072df637b428a737c3c870","lessThan":"491d8c9ac98d55073bda778f88a5248d4cce3fa0","status":"affected","versionType":"git"},{"version":"516e5bd0b6bf4ae1ad072df637b428a737c3c870","lessThan":"775d0f4558f4cec0ee0c8966595d1add1791f36e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/mbox.c","drivers/cxl/core/mce.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h","drivers/cxl/cxlmem.h"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5563db13c9528a56c7161260ec75ec8690dc5608"},{"url":"https://git.kernel.org/stable/c/491d8c9ac98d55073bda778f88a5248d4cce3fa0"},{"url":"https://git.kernel.org/stable/c/775d0f4558f4cec0ee0c8966595d1add1791f36e"}],"title":"cxl/mce: Make the MCE notifier per-region","x_generator":{"engine":"bippy-1.2.0"}}}}