Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc

Variable vector[] is declared on stack in function dmsintc_inject_irq()
and sometimes it is used without initialized. Here fix this issue.
Published: 2026-09-16
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the LoongArch KVM driver of the Linux kernel. A stack variable, vector[], is declared in dmsintc_inject_irq() and may be utilized before it is initialized. An attacker could trigger this code path and cause unpredictable behavior, potentially corrupting memory or bringing the virtual machine under the KVM host to a non‑responsive state. The flaw does not directly expose secrets, but the erratic behavior can deny service to the affected virtual machine or host.

Affected Systems

The flaw affects all Linux kernel builds that include the LoongArch KVM code. Vendor information is listed as Linux:Linux. No specific kernel version range is documented in the CVE data; therefore, any kernel version containing the LoongArch KVM module could be susceptible.

Risk and Exploitability

The CVSS score of 7.3 indicates moderate to high severity. The EPSS score of less than 1% implies a very low overall probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need the ability to run code within the KVM host or control a guest that can trigger the uninitialized variable usage, making the attack vector likely local or requiring elevated privileges. No user‑directed exploitation vector is documented, so the threat is focused on hosts that run KVM on LoongArch platforms.

Generated by OpenCVE AI on September 18, 2026 at 07:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patches from https://git.kernel.org/stable/c/81aa3a58b542ed88819115c80a17acd86eacb89d and https://git.kernel.org/stable/c/f56060b0e10fa5633fac1dc243a25da3a5cdafb1 which address the uninitialized stack variable in dmsintc_inject_irq()
  • Rebuild and install the updated kernel, ensuring the LoongArch KVM module is the patched version
  • Reboot the system to activate the patched kernel

Generated by OpenCVE AI on September 18, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc Variable vector[] is declared on stack in function dmsintc_inject_irq() and sometimes it is used without initialized. Here fix this issue.
Title LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:00.192Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.027

Modified: 2026-09-16T15:18:17.177

Link: CVE-2026-89910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable