{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92522","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.874Z","datePublished":"2026-09-17T16:10:28.823Z","dateUpdated":"2026-09-18T17:55:37.542Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:37.542Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor: validate MADT IOAPIC entry bounds\n\nThe IOAPIC hotplug lookup parses both MADT and _MAT records directly.\nThe MADT walk previously used a subtable's declared length to advance\nthe cursor after only locating a generic header.  The _MAT path likewise\npassed a generic header to the IOAPIC helper.\n\nValidate that a current record has a complete generic header, that its\ndeclared length is contained in the available record range, and that a\ntyped IOAPIC record contains the full fixed IOAPIC body before reading\nits fields.  Use the same relation for both MADT and _MAT provider\npaths."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The triggering bytes are MADT IO_APIC subtable headers (hdr->length/type) and _MAT buffers parsed by parse_madt_ioapic_entry()/parse_mat_ioapic_entry() from acpi_get_ioapic_id(), called by acpi_register_ioapic() via handle_ioapic_add() during pcibios_assign_resources() and acpi_pci_root_add() hotadd. They arrive from firmware or a hypervisor ACPI blob, not a network protocol message.\nAC:L - A MADT subtable with length 0 makes parse_madt_ioapic_entry() add hdr->length each iteration and never exit. A type-ACPI_MADT_TYPE_IO_APIC record whose length is only sizeof(acpi_subtable_header) makes get_ioapic_id() read the 12-byte acpi_madt_io_apic body past the record. Both are deterministic with no race.\nPR:N - acpi_get_ioapic_id() runs from fs_initcall(pcibios_assign_resources) through pci_assign_unassigned_resources()->acpi_ioapic_add() with no capable() or credential check. A crafted MADT from get_madt_table() or a _MAT buffer from acpi_evaluate_object() is consumed automatically; no Linux account or user-namespace capability is required.\nUI:N - After the MADT/_MAT is in place, pcibios_assign_resources() and acpi_pci_root_add() (hotadd when system_state==SYSTEM_RUNNING) walk ACPI0009/ACPI000A devices in handle_ioapic_add() and call acpi_register_ioapic() with no victim mount, open, or other interactive action.\nS:U - get_ioapic_id() over-reads and parse_madt_ioapic_entry() hangs inside the same kernel that owns the MADT mapping and the _MAT ACPI buffer. This is not a KVM guest-to-host escape, IOMMU/DMA bypass, or sandbox crossing.\nC:L - get_ioapic_id() reads ioapic->id, ioapic->address, and ioapic->global_irq_base from a 12-byte acpi_madt_io_apic while only a 2-byte acpi_subtable_header was shown to fit in the MADT range or _MAT obj->buffer.length. That is a strictly bounded few-byte over-read, not an arbitrary kernel read.\nI:L - On a gsi_base match, get_ioapic_id() writes the over-read ioapic->id into *ioapic_id, and acpi_register_ioapic() passes it to mp_register_ioapic() which stores it in ioapics[].mp_config.apicid. That is limited IRQ metadata modification, not an out-of-bounds write or control-flow hijack primitive.\nA:H - parse_madt_ioapic_entry() infinite-loops when hdr->length is 0, hanging fs_initcall(pcibios_assign_resources) or PCI-root hotplug. get_ioapic_id()'s 12-byte read past a MADT mapping or _MAT heap buffer can also oops if the following bytes are unmapped."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/processor_core.c"],"versions":[{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"5601bd81bc290a724ed47797d22c16cba4d7ed9f","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"ff82e3374e9103d046b2a82f4315d9a422ff097d","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"2a5520065e76000f8c979d3d7b3d861ccaaecf1e","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"8e67b58c04990817ac2dbf8ae03353be6a358cd4","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"74d84320f8e37955eb286a7777843d554e6e75b2","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"4d8ecaa332c163f2b44aa5027bf061950b71b5f3","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"355bee5f11acb116cd256588631b4028ca562646","status":"affected","versionType":"git"},{"version":"ecf5636dcd59cd5508641f995cc4c2bafedbb995","lessThan":"2c50ffdc73f3a70d745d249f509fc290754121e6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/processor_core.c"],"versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5601bd81bc290a724ed47797d22c16cba4d7ed9f"},{"url":"https://git.kernel.org/stable/c/ff82e3374e9103d046b2a82f4315d9a422ff097d"},{"url":"https://git.kernel.org/stable/c/2a5520065e76000f8c979d3d7b3d861ccaaecf1e"},{"url":"https://git.kernel.org/stable/c/8e67b58c04990817ac2dbf8ae03353be6a358cd4"},{"url":"https://git.kernel.org/stable/c/74d84320f8e37955eb286a7777843d554e6e75b2"},{"url":"https://git.kernel.org/stable/c/4d8ecaa332c163f2b44aa5027bf061950b71b5f3"},{"url":"https://git.kernel.org/stable/c/355bee5f11acb116cd256588631b4028ca562646"},{"url":"https://git.kernel.org/stable/c/2c50ffdc73f3a70d745d249f509fc290754121e6"}],"title":"ACPI: processor: validate MADT IOAPIC entry bounds","x_generator":{"engine":"bippy-1.2.0"}}}}