Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: ISST: Validate level in perf mask ioctls

isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the
user-provided level as an index into perf_levels[] via
_read_pp_level_info() and _read_bf_level_info(), but neither helper
validates it first.

The adjacent level-info helpers reject levels above max_level before
reading the same per-level register block. Add the same bounds checks to
the mask helpers, and reject disabled SST-PP levels in
isst_if_get_perf_level_mask() to match isst_if_get_perf_level_info().

This prevents out-of-bounds reads from the per-level offset table on
invalid ioctl input.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read
Action: Patch
AI Analysis

Impact

In the Linux kernel, the ISST driver functions isst_if_get_perf_level_mask and isst_if_get_base_freq_mask use a user‑supplied level value directly as an index into a per‑level table without performing bounds checking. This leads to an out‑of‑bounds read from the perf_levels array, a classic CWE‑125 condition. The kernel patch adds the necessary bounds checks and rejects disabled SST‑PP levels, preventing the problematic read.

Affected Systems

The vulnerability affects Linux kernel builds that include the ISST driver and have the SST‑PP feature enabled. Because the kernel source does not specify a limited version range, any unpatched Linux installation that loads the ISST driver or exposes its control interface to user space may be vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The. Based on the description, it is inferred that the out‑of‑bounds read could allow a local attacker to read kernel memory beyond the intended bounds if a malformed ioctl request is sent. The attack vector is therefore local and requires the ability to send crafted ioctl calls to the ISST device.

Generated by OpenCVE AI on September 21, 2026 at 01:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds bounds checks to isst_if_get_perf_level_mask and isst_if_get_base_freq_mask
  • If the patch is not yet available in your kernel release, backport the commits from the provided reference log and rebuild the ISST driver if the feature is not required
  • Ensure any user‑space tools that interact with the ISST device validate ioctl arguments before making the call

Generated by OpenCVE AI on September 21, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _read_bf_level_info(), but neither helper validates it first. The adjacent level-info helpers reject levels above max_level before reading the same per-level register block. Add the same bounds checks to the mask helpers, and reject disabled SST-PP levels in isst_if_get_perf_level_mask() to match isst_if_get_perf_level_info(). This prevents out-of-bounds reads from the per-level offset table on invalid ioctl input.
Title platform/x86: ISST: Validate level in perf mask ioctls
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:53.518Z

Reserved: 2026-09-11T19:38:34.704Z

Link: CVE-2026-89443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:24.737

Modified: 2026-09-14T13:19:01.547

Link: CVE-2026-89443

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:11Z

Links: CVE-2026-89443 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses