Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/features: bound fwctl command payload to the input buffer

fwctl_cmd_rpc() copies cmd->in_len bytes into inbuf = kvzalloc(cmd->in_len)
and passes inbuf and in_len to ->fw_rpc(). The CXL callback cxlctl_fw_rpc()
ignores in_len and never checks the user-controlled op_size against it.

cxlctl_set_feature() bounds op_size only from below
(op_size <= sizeof(feat_in->hdr)) and then reads op_size - sizeof(hdr)
bytes from feat_in->feat_data via cxl_set_feature(). With a small in_len
and a large op_size the first memcpy() already reads past the
kvzalloc(in_len) buffer; the out-of-bounds bytes are placed in the mailbox
payload and sent to the device, and a large enough op_size can walk into
unmapped memory and oops the kernel. The Get paths pin op_size to a fixed
size but likewise read the input struct without checking in_len.

Reject, at the single dispatch point, any request whose fixed header plus
op_size does not fit in the copied-in buffer. The lower-bound test guards
the subtraction and ensures op_size was copied in before it is read.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out-of-bounds read in the Linux kernel’s CXL (Compute Express Link) subsystem. During fwctl command handling the kernel allocates a buffer sized to a user-supplied length but later ignores that length when accessing the buffer, allowing a crafted command to cause a read past the end of the allocated area. This out-of-bounds read can trigger a kernel OOPS and crash, resulting in denial of service.

Affected Systems

All Linux kernel releases that include the cxl/features module before the security fix. Distribution or vendor is not specified; any installation that ships a kernel with the cxl subsystem and has not applied the patch is vulnerable. The problem appears in paths that handle fwctl commands for CXL features, so any system exposing the CXL device interface is at risk. Version information is not provided.

Risk and Exploitability

The CVSS score of 7.1 denotes high severity. The EPSS score is less than 1%, indicating that exploitation in the wild is unlikely, and the vulnerability is not listed in the CISA KEV catalog, so no known active exploits have been reported. Based on the description, the likely attack vector is local access to the CXL interface; an attacker or a compromised privileged process that can issue a crafted fwctl command can trigger the out-of-bounds read, causing the kernel to oops and crash, leading to denial of service. No privilege escalation or remote code execution is described.

Generated by OpenCVE AI on September 15, 2026 at 21:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that corrects the bounds checks in cxlctl_fw_rpc and cxlctl_set_feature to prevent the out-of-bounds read.
  • If a patch is not immediately available, disable the CXL subsystem or restrict access to the device file so that only trusted users can issue fwctl commands.
  • Monitor kernel logs for OOPS or panic events related to CXL and configure alerts for abnormal activity; consider using a security module such as SELinux or AppArmor to enforce strict access control on the CXL device.

Generated by OpenCVE AI on September 15, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/features: bound fwctl command payload to the input buffer fwctl_cmd_rpc() copies cmd->in_len bytes into inbuf = kvzalloc(cmd->in_len) and passes inbuf and in_len to ->fw_rpc(). The CXL callback cxlctl_fw_rpc() ignores in_len and never checks the user-controlled op_size against it. cxlctl_set_feature() bounds op_size only from below (op_size <= sizeof(feat_in->hdr)) and then reads op_size - sizeof(hdr) bytes from feat_in->feat_data via cxl_set_feature(). With a small in_len and a large op_size the first memcpy() already reads past the kvzalloc(in_len) buffer; the out-of-bounds bytes are placed in the mailbox payload and sent to the device, and a large enough op_size can walk into unmapped memory and oops the kernel. The Get paths pin op_size to a fixed size but likewise read the input struct without checking in_len. Reject, at the single dispatch point, any request whose fixed header plus op_size does not fit in the copied-in buffer. The lower-bound test guards the subtraction and ensures op_size was copied in before it is read.
Title cxl/features: bound fwctl command payload to the input buffer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:09.007Z

Reserved: 2026-09-11T19:38:34.726Z

Link: CVE-2026-89571

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.160

Modified: 2026-09-13T07:17:23.097

Link: CVE-2026-89571

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:40Z

Links: CVE-2026-89571 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses