Description
In the Linux kernel, the following vulnerability has been resolved:

fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write

The trailing byte path in altera_cvp_send_block() dereferences a u32
pointer even when only 1-3 bytes remain in the input buffer. If the buffer
ends at a page or scatterlist boundary, this can read past the valid image
data and fault.

Copy the remaining bytes into a zero-initialized u32 before writing the
final word so only valid bytes are read from the input buffer.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

FPGA firmware, used in the altera_cvp module, performs an out‑of‑bounds read when it writes the last partial word of a firmware image. The code dereferences a 32‑bit pointer even when only one to three bytes are left in the input buffer. If the remaining bytes align with a page or scatter list boundary, the read can slip past the valid image data and trigger a kernel fault. Based on the description, it is inferred that this fault will trigger a kernel panic leading to a denial of service on the affected system.

Affected Systems

All Linux kernel builds that ship the default altera_cvp firmware module are affected. The affected devices include standard Linux distributions as well as custom builds that compile the kernel with the legacy altera_cvp driver. The patch has been merged into mainline; therefore, any kernel version that includes or later than the commit 4dc1051939e499c838229af035464a5fc7671198 is considered compliant. Based on the presence of the merge commit URL, it is inferred that the fix has reached the mainline kernel.

Risk and Exploitability

The CVSS score of 4.4 indicates a low severity, while the EPSS score is reported as less than 1%, signaling a very low probability of exploitation in the wild. The KEV catalog does not list this vulnerability. An attacker would need the ability to load a crafted or malformed firmware image into the FPGA, which requires write access to the device file or the firmware update interface. Based on the description, it is inferred that this fault will trigger a kernel panic leading to a denial of service on the affected system.

Generated by OpenCVE AI on September 15, 2026 at 19:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the altera_cvp patch from commit 4dc1051939e499c838229af035464a5fc7671198
  • If a custom kernel is used or a newer kernel cannot be obtained, apply the patch manually by copying the changes from commit 4dc1051939e499c838229af035464a5fc7671198 into the kernel source tree and rebuild the kernel
  • If FPGA functionality is not required, disable or blacklist the altera_cvp kernel module so the vulnerable driver is never loaded

Generated by OpenCVE AI on September 15, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write The trailing byte path in altera_cvp_send_block() dereferences a u32 pointer even when only 1-3 bytes remain in the input buffer. If the buffer ends at a page or scatterlist boundary, this can read past the valid image data and fault. Copy the remaining bytes into a zero-initialized u32 before writing the final word so only valid bytes are read from the input buffer.
Title fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:19.217Z

Reserved: 2026-09-11T19:38:34.760Z

Link: CVE-2026-89730

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:03.363

Modified: 2026-09-14T13:19:22.170

Link: CVE-2026-89730

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:40Z

Links: CVE-2026-89730 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses