Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: ISST: Add a NULL check for sst_inst[]

To be consistent with other places, add a NULL check for failed socket
loading by checking isst_common.sst_inst[].
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel ISST driver contains a null pointer dereference. When a socket load fails, the driver accesses the sst_inst[] array without checking for a null value, which can cause the kernel to crash. This crash results in a loss of system availability and may require a reboot to recover.

Affected Systems

The vulnerability applies to any Linux kernel build that does not contain the recent patch adding the NULL check for sst_inst[]. All system configurations running such kernel versions are at risk, regardless of architecture, as the defect lies in the platform/x86 ISST driver.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a not specify an attack vector, but the failure mode involves a kernel crash triggered the description, it is inferred that exploitation would require local activity that triggers the problematic socket load and likely privileged or elevated permissions to observe the impact.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Linux kernel version that includes the commit adding the NULL check for sst_inst[].
  • Reboot the system so that the updated driver is loaded into memory.
  • Enable automatic kernel security updates or maintain a schedule to manually apply kernel patches promptly.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] To be consistent with other places, add a NULL check for failed socket loading by checking isst_common.sst_inst[].
Title platform/x86: ISST: Add a NULL check for sst_inst[]
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:08.745Z

Reserved: 2026-09-11T19:38:34.703Z

Link: CVE-2026-89439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:24.203

Modified: 2026-09-11T20:19:24.203

Link: CVE-2026-89439

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:08Z

Links: CVE-2026-89439 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses