{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89588","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.729Z","datePublished":"2026-09-11T19:44:52.842Z","dateUpdated":"2026-09-13T06:31:24.106Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:24.106Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: APEI: GHES: fix ARM section length accounting after header\n\nIn ghes_handle_arm_hw_error(), after skipping the cper_sec_proc_arm\nheader with (err + 1), the remaining length was reduced by sizeof(err)\n(pointer size) instead of sizeof(*err) (structure size).\n\nThat overestimates the bytes left for cper_arm_err_info records and can\nlet the parser read past the CPER section when err_info_num is large\nenough relative to error_data_length.\n\nUse sizeof(*err) so the length accounting matches the pointer advance\nand the earlier sizeof(*err) size check."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - GHES ARM processor CPER sections are consumed on the local host from ACPI APEI notifications (SCI, GSIV, GPIO, SEA, SDEI, NMI, or poll) via ghes_proc()/ghes_proc_in_irq() into ghes_handle_arm_hw_error(); there is no network or radio path. The most severe case is a local ARM server or VM whose firmware delivers a crafted ARM section.\nAC:L - After skipping the cper_sec_proc_arm header, remaining length was reduced by sizeof(pointer) (8) instead of sizeof(*err) (40), over-counting by 32 bytes. A recoverable ARM section with err_info_num large relative to error_data_length then deterministically parses past the section; no race or attacker-uncontrollable layout is required.\nPR:N - ghes_do_proc() and ghes_handle_arm_hw_error() apply no capability or credential check; firmware-first RAS notifications are processed in IRQ, NMI, or kworker context without a host login. Compromised ACPI/SDEI firmware or a BMC-written GHES status block needs no Linux account, matching other firmware-sourced kernel CNA scores.\nUI:N - GHES consumes the CPER record automatically on the notification and irq_work path. No victim action such as mounting a filesystem, opening a device node, or confirming a prompt is required.\nS:U - The out-of-bounds parse and any memory_failure() side effects remain in the host kernel that handles GHES. This is not a KVM/Xen guest-to-host escape or an IOMMU/DMA boundary bypass.\nC:H - The inflated remaining length lets the parser read a cper_arm_err_info object past the CPER section. On the SEA/NMI path the estatus node is allocated to the exact CPER size, so this is a kernel gen_pool/heap out-of-bounds read of adjacent objects, including pointers.\nI:H - Out-of-bounds err_info fields are interpreted as a processor cache-error record; if type and validation_bits match, ghes_do_memory_failure() poisons err_info->physical_fault_addr taken from adjacent memory. Firmware-controlled neighboring bytes thus yield a kernel integrity primitive via HWPoison of arbitrary PFNs.\nA:H - Reading past an exact-sized ghes_estatus_pool node can hit unmapped memory and oops, as the related ARM GHES parser already did on QEMU. memory_failure() of kernel pages or a large err_info_num walk in IRQ context can panic or hang, and notifications can be repeated."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/apei/ghes.c"],"versions":[{"version":"242c652849d979d0133c315a42d9acea0ff88390","lessThan":"5ff385e9403e87ae33f65b8c38698d3b1e92cfde","status":"affected","versionType":"git"},{"version":"136093ba4161e0080088abff48273f6830a47766","lessThan":"452eb28e03015abec6d4bf6488ee567706ade4e1","status":"affected","versionType":"git"},{"version":"87880af2d24e62a84ed19943dbdd524f097172f2","lessThan":"b48b613073c3d652cb1823c15d16f7067cf4cee4","status":"affected","versionType":"git"},{"version":"87880af2d24e62a84ed19943dbdd524f097172f2","lessThan":"903308ea40adf0577d82eab69882faf8836326ce","status":"affected","versionType":"git"},{"version":"db103b8bd3a4aca69b1b5fe8831a6ed75ac4b3bd","status":"affected","versionType":"git"},{"version":"6.12.75","lessThan":"6.12.109","status":"affected","versionType":"semver"},{"version":"6.18.16","lessThan":"6.18.50","status":"affected","versionType":"semver"},{"version":"6.19.6","lessThan":"6.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/apei/ghes.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.75","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.16","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5ff385e9403e87ae33f65b8c38698d3b1e92cfde"},{"url":"https://git.kernel.org/stable/c/452eb28e03015abec6d4bf6488ee567706ade4e1"},{"url":"https://git.kernel.org/stable/c/b48b613073c3d652cb1823c15d16f7067cf4cee4"},{"url":"https://git.kernel.org/stable/c/903308ea40adf0577d82eab69882faf8836326ce"}],"title":"ACPI: APEI: GHES: fix ARM section length accounting after header","x_generator":{"engine":"bippy-1.2.0"}}}}