Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from
the RCRB MMIO block using a readl() loop bounded by sizeof(struct
aer_capability_regs). This struct is a software layout and its embedded
struct pcie_tlp_log is larger than the on-wire AER capability. As a
result the loop reads past the mapped AER register block.

The over-read also populates the software-only tail fields including
header_log.header_len. An out-of-range header_len passed to
pcie_print_tlp_log() can then loop past the header log buffer and cause
a second out-of-bounds read.

The read was correct when introduced, but struct pcie_tlp_log has since
grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),
so sizeof(struct aer_capability_regs) no longer matches the physical AER
capability.

Bound the read to the physical AER registers, header through the 16 byte
Header Log. Zero the destination first so the software-only fields are
deterministic.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

cxl_rch_get_aer_info() copies an AER capability block using a loop based on sizeof(struct aer_capability_regs). The struct includes a pcie_tlp_log field that is larger than the on‑wire AER register block, so the loop reads beyond the mapped register region. The over‑read populates software‑only tail fields such as header_log.header_len, which can be leveraged by pcie_print_tlp_log() to perform a second out‑of‑bounds read. This flaw enables an attacker to read kernel memory, potentially leaking confidential data.

Affected Systems

Any Linux kernel image that includes the cxl/ras driver and has not incorporated the patch that bounds the read to the physical AER registers is vulnerable. No any distribution exposing a CXL Root Complex Host device with the unpatched driver should be examined for susceptibility.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate‑to‑high severity, while the EPSS <1% and absence from the CISA KEV catalog suggest a low likelihood of real‑world exploitation. The vulnerability requires local privilege or the ability to influence interactions with a CXL RCH device, limiting the attack surface. Consequently, the overall risk is considered moderate, driven primarily by the restricted attack vector and low exploitation probability.

Generated by OpenCVE AI on September 15, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the cxl/ras patch, which bounds the AER register read and zeroes the buffer before copying.
  • If a kernel upgrade cannot be performed promptly, disable the cxl/ras driver or unload the cxl module to prevent the vulnerable code from executing. This can be done by adding 'blacklist cxl' to /etc/modprobe.d/ or rebuilding the kernel with CONFIG_CXL disabled if production systems do not require CXL support.
  • Restrict access to /dev/cxl_* device nodes, ensuring only trusted users or services can interact with CXL RCH devices, thereby limiting the potential for an attacker to trigger the over‑read.

Generated by OpenCVE AI on September 15, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block. The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read. The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability. Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.
Title cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:55.911Z

Reserved: 2026-09-11T19:38:34.760Z

Link: CVE-2026-89731

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:03.487

Modified: 2026-09-21T14:17:26.173

Link: CVE-2026-89731

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:41Z

Links: CVE-2026-89731 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses