Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: KVM: Validate MSI data before routing it to EIOINTC

pch_msi_set_irq() passes e->msi.data straight into eiointc_set_irq() as
the irq number. The MSI data comes from userspace, that either via a
KVM_IRQ_ROUTING_MSI entry set with KVM_SET_GSI_ROUTING (used by irqfd
and KVM_IRQ_LINE) or directly via KVM_SIGNAL_MSI, and is never checked
against EIOINTC_IRQS.

eiointc_set_irq() uses the value with __set_bit()/__clear_bit() on the
256-bit isr bitmap, eiointc_update_irq() then indexes sw_coremap[] and
the per-cpu coreisr/sw_coreisr bitmaps with it. Therefore a data value
>= 256 reads and writes memory past the end of those arrays, i.e. any
process holding a VM fd can corrupt kernel memory beyond the allocation
of loongarch_eiointc.

Reject MSI data that doesn't fit in the EIOINTC irq space. The DMSINTC
path is unaffected as it decodes the vector from the address and masks
it.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s LoongArch KVM implementation does not validate MSI data before passing it to the EIOINTC interrupt controller. MSI data, supplied by a guest VM through ioctl calls such as KVM_SET_GSI_ROUTING or KVM_SIGNAL_MSI, is interpreted as an interrupt index without bounds checking. When the supplied value exceeds the 256‑interrupt range, the code performs out‑of‑bounds writes to kernel memory structures, potentially corrupting the kernel and allowing an attacker to execute arbitrary code with kernel privileges. This flaw is a classic input‑validation and out‑of‑bounds write weakness.

Affected Systems

The vulnerability exists in the Linux kernel source for the LoongArch architecture. Any kernel build on LoongArch that includes KVM MSI routing and has not incorporated the patch series referenced in the advisory is affected. No specific release versions are enumerated in the CVE data.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is of high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker must be able to create or control a KVM guest and issue the relevant ioctl calls to /dev/kvm. Once that condition is met, the attacker can supply an MSI number outside the valid range, inducing kernel memory corruption. Attack requires local or VM‑level access and can result in privilege escalation or VM‑escape, but it does not rely on network exposure.

Generated by OpenCVE AI on September 18, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that validates MSI data before routing it to EIOINTC; upgrade to a kernel version that includes the commit series linked in the advisories.
  • Restrict access to /dev/kvm and the KVM_SET_GSI_ROUTING / KVM_SIGNAL_MSI ioctl interfaces by setting appropriate file‑system permissions or using an access‑control mechanism, ensuring only trusted users can configure MSI routing.
  • If a recent kernel update is not immediately available, disable MSI routing for virtual machines—remove KVM_SET_GSI_ROUTING entries or configure VMs to use legacy IRQ mode—so that the vulnerable code path is not exercised.

Generated by OpenCVE AI on September 18, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-787

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate MSI data before routing it to EIOINTC pch_msi_set_irq() passes e->msi.data straight into eiointc_set_irq() as the irq number. The MSI data comes from userspace, that either via a KVM_IRQ_ROUTING_MSI entry set with KVM_SET_GSI_ROUTING (used by irqfd and KVM_IRQ_LINE) or directly via KVM_SIGNAL_MSI, and is never checked against EIOINTC_IRQS. eiointc_set_irq() uses the value with __set_bit()/__clear_bit() on the 256-bit isr bitmap, eiointc_update_irq() then indexes sw_coremap[] and the per-cpu coreisr/sw_coreisr bitmaps with it. Therefore a data value >= 256 reads and writes memory past the end of those arrays, i.e. any process holding a VM fd can corrupt kernel memory beyond the allocation of loongarch_eiointc. Reject MSI data that doesn't fit in the EIOINTC irq space. The DMSINTC path is unaffected as it decodes the vector from the address and masks it.
Title LoongArch: KVM: Validate MSI data before routing it to EIOINTC
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:57.195Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89907

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.703

Modified: 2026-09-16T15:18:16.810

Link: CVE-2026-89907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses