Description
In the Linux kernel, the following vulnerability has been resolved:

mailbox: riscv-sbi-mpxy: validate RPMI notification lengths

The SBI return value controls how many bytes are copied from shared
memory into the RPMI notification buffer. It is not validated against
the negotiated shared-memory size before that copy. The event walker
also uses a reversed loop condition and can inspect a short event record.

Validate the complete notification length before copying it, iterate only
while a full event header remains, and stop when a declared event payload
extends beyond the copied notification data.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel defect in the riscv‑sbi‑mpxy mailbox interface causes the SBI return value to dictate how many bytes are copied from shared memory into the RPMI notification buffer without first validating that this length is within the negotiated shared‑memory size. Because the event walker uses a reversed loop condition, it can read a partial event record that exceeds the bounds of the copied notification. This unchecked length leads to a buffer overflow within the kernel, which can crash the system or corrupt memory, resulting in a denial‑of‑service condition. The weakness originates from failing to validate external input and is related to CWE‑20 and CWE‑119.

Affected Systems

All Linux kernel releases that deploy the riscv‑sbi‑mpxy mailbox interface are potentially affected. The vendor product in question is the Linux kernel itself; specific affected versions are unspecified in the advisory, so all distributions running Linux on RISC‑V hardware that include this interface may be vulnerable until patched.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. Although the EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, the weakness can be exploited by any user able to inject malformed RPMI notifications into the shared‑memory region used by the mailbox. Because the mutation occurs in kernel space, the requisite attack vector is local and requires privilege or the ability to influence the mailbox content. The low exploitation probability suggests this is not a widely leveraged attack, but the potential for a critical denial‑of‑service makes a timely patch important.

Generated by OpenCVE AI on September 20, 2026 at 02:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the fix for the riscv‑sbi‑mpxy mailbox interface.
  • Disable the riscv‑sbi‑mpxy mailbox interface if it is not required, eliminating the vulnerable code path.
  • Restrict any processes that can write to the shared memory region used by the mailbox to trusted, privileged users only.

Generated by OpenCVE AI on September 20, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notification lengths The SBI return value controls how many bytes are copied from shared memory into the RPMI notification buffer. It is not validated against the negotiated shared-memory size before that copy. The event walker also uses a reversed loop condition and can inspect a short event record. Validate the complete notification length before copying it, iterate only while a full event header remains, and stop when a declared event payload extends beyond the copied notification data.
Title mailbox: riscv-sbi-mpxy: validate RPMI notification lengths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:38.782Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:13.810

Modified: 2026-09-18T18:17:45.823

Link: CVE-2026-90191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-20

    Improper Input Validation