Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Fix acpi_package_ids[] array overflow

With LoongArch virt machine, a typical setting is one core per socket,
there will max 256 sockets (packages) on one VM. With PPTT acpi table,
array acpi_package_ids[] will be overflowed.

Here change the array size of acpi_package_ids[] with the max value of
MAX_PACKAGES and KVM_MAX_VCPUS.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a buffer overflow in the acpi_package_ids array used by the LoongArch architecture when a virtual machine is configured with many sockets. The array was sized to accommodate fewer packages than a LoongArch VM can expose, allowing a PPTT ACPI table to overflow the bounds of the array. The overflow can corrupt kernel memory, potentially leading to a denial of service or privilege escalation if an attacker can influence the ACPI data presented to the kernel.

Affected Systems

All Linux kernel builds that support the LoongArch architecture are affected, including mainstream distributions that ship the kernel for this architecture. The issue manifests when a virtual machine is configured with one core per socket and a maximum of 256 sockets (packages) per VM on the LoongArch virt platform with PPTT ACPI tables. Version information is not explicitly listed but any kernel that compiles for LoongArch and processes PPTT tables without the patch is vulnerable.

Risk and Exploitability

The CVSS score of 8.4 classifies the flaw as high severity, indicating serious potential damage. The EPSS score is below 1 %, suggesting that the probability of exploitation in the near term is low; however, the flaw is not listed in the CISA KEV catalog. The likely attack vector involves an attacker having control over the virtual machine configuration or the ACPI tables supplied to the kernel, allowing an overflow that could compromise the guest operating system. Because kernel memory corruption can lead to arbitrary code execution or system crash, the impact is significant if exploitation occurs.

Generated by OpenCVE AI on September 18, 2026 at 03:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the patch for LoongArch acpi_package_ids overflow.
  • If an immediate kernel update cannot be performed, configure virtual machines to use fewer than 256 sockets or reduce KVM_MAX_VCPUS so that acpi_package_ids size is never exceeded.
  • Verify that PPTT ACPI tables are not served to the kernel when the machine is under attack or consider disabling PPTT support in the kernel configuration.

Generated by OpenCVE AI on September 18, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix acpi_package_ids[] array overflow With LoongArch virt machine, a typical setting is one core per socket, there will max 256 sockets (packages) on one VM. With PPTT acpi table, array acpi_package_ids[] will be overflowed. Here change the array size of acpi_package_ids[] with the max value of MAX_PACKAGES and KVM_MAX_VCPUS.
Title LoongArch: Fix acpi_package_ids[] array overflow
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:54.093Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.380

Modified: 2026-09-16T15:18:16.567

Link: CVE-2026-89904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses

No weakness.