Description
In the Linux kernel, the following vulnerability has been resolved:

x86/tdx: Fix off-by-one in port I/O handling

handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use:

u64 mask = GENMASK(BITS_PER_BYTE * size, 0);

GENMASK(h, l) includes bit h. For size=1 (INB), this produces
GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8
bits). The mask is one bit too wide for all I/O sizes.

Fix the mask calculation.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity
Action: Apply Patch
AI Analysis

Impact

An off‑by‑one error in the kernel’s TDX port I/O handlers causes the mask used for 8‑bit access to be one bit too wide, producing a 9‑bit mask instead of the intended 8 bits. This leads to incorrect data being read from or written to I/O ports, potentially corrupting kernel data. Based on the description, it is inferred that exploitation requires local kernel privilege or a user with TDX port I/O access.

Affected Systems

The issue is confined to the Linux kernel on x86 architectures where arch/x86/coco/tdx/tdx.c is compiled. Any kernel build that has not incorporated the patch is vulnerable; the CPE entry identifies the general Linux kernel product but does not specify affected version ranges.

Risk and Exploitability

Based on the description, it is inferred that exploitation requires local kernel privilege or a user with TDX port I/O access. The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires local kernel access or a privileged actor capable of performing TDX port I/O, with no known remote code execution path. Thus the risk is considered low to moderate, depending on the environment.

Generated by OpenCVE AI on September 15, 2026 at 19:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that includes the TDX port I/O mask bug fix.
  • If staying on an older kernel, manually apply the upstream patch from the Linux source tree before using TDX I/O.
  • Disable or restrict TDX port I/O if it is not required, by removing the relevant module or disabling the kernel configuration that enables it.

Generated by OpenCVE AI on September 15, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-193
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use: u64 mask = GENMASK(BITS_PER_BYTE * size, 0); GENMASK(h, l) includes bit h. For size=1 (INB), this produces GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8 bits). The mask is one bit too wide for all I/O sizes. Fix the mask calculation.
Title x86/tdx: Fix off-by-one in port I/O handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:31.014Z

Reserved: 2026-09-11T19:38:34.762Z

Link: CVE-2026-89751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:06.013

Modified: 2026-09-14T13:19:23.783

Link: CVE-2026-89751

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:55Z

Links: CVE-2026-89751 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses