Description
In the Linux kernel, the following vulnerability has been resolved:

PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()

pci_write_legacy_io() loads 4 bytes from the kernfs write buffer
regardless of how many bytes userspace wrote:

if (count != 1 && count != 2 && count != 4)
return -EINVAL;

return pci_legacy_write(bus, off, *(u32 *)buf, count);

kernfs_fop_write_iter() allocates the buffer with kmalloc(len + 1),
so a 1-byte write to the legacy_io sysfs file allocates 2 bytes and
the unconditional u32 load reads up to 2 bytes past the end of the
allocation, which KASAN reports as a slab-out-of-bounds read.
Similarly, a 2-byte write overreads by 1 byte.

Thus, read only the number of bytes requested using get_unaligned_le16()
and get_unaligned_le32() for the 2 and 4 byte cases, interpreting the
buffer as little-endian to match the byte ordering of PCI I/O port
space.

The PowerPC implementation previously compensated for the generic
code's native-endian 32-bit load by shifting the value into place
for the 1 and 2 byte cases. The shifts were only correct on
big-endian kernels.

On little-endian PowerPC (POWER8 and later), they extracted the wrong
bytes, so a 1-byte write wrote an out-of-bounds byte instead of the
requested value. On big-endian, the native load also caused out_le16()
and out_le32() to reverse the user's bytes on the wire for 2 and 4 byte
writes. The little-endian helpers resolve both issues, so the shifts
are removed.

No changes are needed for the Alpha platform.

The legacy_io file is root-only and exists only on Alpha and PowerPC,
the two architectures that define HAVE_PCI_LEGACY.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read in kernel buffer
Action: Upgrade Kernel
AI Analysis

Impact

The flaw occurs in the PCI/legacy_io sysfs interface of the Linux kernel when a user writes one‑ or two‑byte values. The kernel unconditionally loads four bytes from the user‑supplied buffer, causing an out‑of‑bounds read of up to two bytes. This read leaks kernel memory contents, representing a potential information‑disclosure vulnerability per CWE‑125. The bug does not provide a direct code‑execution path, but it could be leveraged by a root user to obtain sensitive data from the kernel space.

Affected Systems

The affected code is part of the Linux kernel on architectures that implement legacy PCI I/O support, namely Alpha and PowerPC. The legacy_io sysfs file exists only on those architectures and is writable only by root. Users of older kernel releases that contain the buggy pci_write_legacy_io implementation may be impacted, while newer kernels have integrated the endian‑aware load fix. The issue does not affect other processor families or the Alpha platform’s software because its implementation remains unchanged.

Risk and Exploitability

The CVSS score of 4.7 classifies this as a medium‑severity problem. The EPSS score is below 1 %, and the vulnerability is not listed in CISA KEV, indicating that there is no currently known widespread exploitation. An attacker would need elevated privileges to trigger the out‑of‑bounds read, so typical unprivileged users face a low risk. However, on systems where root access is compromised or where legacy PCI I/O operations are required, the leakage of kernel memory could be significant.

Generated by OpenCVE AI on September 15, 2026 at 19:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the pci_write_legacy_io fix
  • If legacy PCI I/O is unnecessary, disable HAVE_PCI_LEGACY in the kernel configuration
  • Remove the legacy_io sysfs entry or restrict its permissions to prevent unnecessary access by privileged users

Generated by OpenCVE AI on September 15, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() pci_write_legacy_io() loads 4 bytes from the kernfs write buffer regardless of how many bytes userspace wrote: if (count != 1 && count != 2 && count != 4) return -EINVAL; return pci_legacy_write(bus, off, *(u32 *)buf, count); kernfs_fop_write_iter() allocates the buffer with kmalloc(len + 1), so a 1-byte write to the legacy_io sysfs file allocates 2 bytes and the unconditional u32 load reads up to 2 bytes past the end of the allocation, which KASAN reports as a slab-out-of-bounds read. Similarly, a 2-byte write overreads by 1 byte. Thus, read only the number of bytes requested using get_unaligned_le16() and get_unaligned_le32() for the 2 and 4 byte cases, interpreting the buffer as little-endian to match the byte ordering of PCI I/O port space. The PowerPC implementation previously compensated for the generic code's native-endian 32-bit load by shifting the value into place for the 1 and 2 byte cases. The shifts were only correct on big-endian kernels. On little-endian PowerPC (POWER8 and later), they extracted the wrong bytes, so a 1-byte write wrote an out-of-bounds byte instead of the requested value. On big-endian, the native load also caused out_le16() and out_le32() to reverse the user's bytes on the wire for 2 and 4 byte writes. The little-endian helpers resolve both issues, so the shifts are removed. No changes are needed for the Alpha platform. The legacy_io file is root-only and exists only on Alpha and PowerPC, the two architectures that define HAVE_PCI_LEGACY.
Title PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:24:09.318Z

Reserved: 2026-09-11T19:38:34.759Z

Link: CVE-2026-89722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:01.370

Modified: 2026-09-13T07:17:37.507

Link: CVE-2026-89722

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:34Z

Links: CVE-2026-89722 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses