Description
In the Linux kernel, the following vulnerability has been resolved:

irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing

In gic_acpi_parse_iaffid() a given MADT GICC entry might not correspond
to a logical cpu recognized by the kernel, resulting in the cpu variable
initialization to an error value.

Currently, the get_logical_index() return value is not checked for failure,
which might result in out-of-bounds memory corruption while trying to
index a per_cpu variable array.

Add a check to evaluate get_logical_index() return value.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation via kernel memory corruption
Action: Apply patch
AI Analysis

Impact

A buffer overflow occurs in the Linux kernel’s ACPI parser for GICC entries when the get_logical_index() function returns an error value that is not checked. The unchecked return allows a malformed IAFFID entry to index a per_cpu variable array out of bounds, corrupting kernel memory and potentially enabling elevated code execution or system crash. The vulnerability is strictly a kernel‑level issue and can be leveraged only within a local environment where an attacker can influence the ACPI tables seen by the kernel at boot or runtime.

Affected Systems

All Linux kernel releases that contain the unpatched gic_acpi_parse_iaffid path are affected. The specific affected versions were not enumerated in the advisory; any version of the kernel before the commit that added the return‑value check is vulnerable.

Risk and Exploitability

The CVSS score of 8.4 signals a high‑severity flaw, while the EPSS score of less than 1% indicates that the likelihood of exploitation in the wild is low at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply malicious ACPI tables or firmware to trigger the overflow, so the practical attack vector is local control; remote exploitation is not supported by the information provided. The patch introduces a defensive check, reducing the risk by preventing the out‑of‑bounds access.

Generated by OpenCVE AI on September 20, 2026 at 02:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the fix added in commit 328affc639ce9873a7a0a3fd6b8339f19767529b
  • Reboot the system to ensure the patched kernel is running
  • Verify that no custom ACPI tables or insecure firmware are loaded, as malformed IAFFID entries would still trigger the vulnerability in older kernels

Generated by OpenCVE AI on September 20, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing In gic_acpi_parse_iaffid() a given MADT GICC entry might not correspond to a logical cpu recognized by the kernel, resulting in the cpu variable initialization to an error value. Currently, the get_logical_index() return value is not checked for failure, which might result in out-of-bounds memory corruption while trying to index a per_cpu variable array. Add a check to evaluate get_logical_index() return value.
Title irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:09.058Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.200

Modified: 2026-09-18T18:17:42.750

Link: CVE-2026-90120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses