Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: processor: validate MADT IOAPIC entry bounds

The IOAPIC hotplug lookup parses both MADT and _MAT records directly.
The MADT walk previously used a subtable's declared length to advance
the cursor after only locating a generic header. The _MAT path likewise
passed a generic header to the IOAPIC helper.

Validate that a current record has a complete generic header, that its
declared length is contained in the available record range, and that a
typed IOAPIC record contains the full fixed IOAPIC body before reading
its fields. Use the same relation for both MADT and _MAT provider
paths.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel crash or data corruption
Action: Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s ACPI processor code allows an attacker to exploit improperly validated ACPI tables. The code previously parsed MADT and _MAT records without ensuring that the declared length of a record was fully contained within the available data. By injecting malformed or truncated ACPI tables, an attacker could cause the kernel to read or write outside the bounds of the intended data structure, potentially leading to a kernel crash, data corruption, or information disclosure. The flaw resides in the ACPI subsystem’s Ioapic entry handling and directly affects the integrity of kernel memory.

Affected Systems

This issue impacts systems running the Linux kernel, irrespective of distribution. Any machine that processes ACPI tables—typically x86 desktop or server hardware—could be affected if the kernel version lacks the patch commit referenced in the advisory. The correction applies to all current releases before the included patch, regardless of vendor RPM versioning, so administrators should verify their kernel version against the upstream kernel commit list.

Risk and Exploitability

The CVSS score of 7.3 reflects a high impact kernel bug. The EPSS score is reported as less than 1%, indicating a low probability of widespread real-world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been disclosed. Attackers would need local access to inject malicious ACPI tables, possibly during system boot or through a compromised firmware update, making the attack vector relatively constrained and less likely to be used by the broader threat landscape.

Generated by OpenCVE AI on September 19, 2026 at 16:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the ACPI IOAPIC bounds validation patch for CVE-2026-92522.
  • Rebuild and deploy the updated kernel configuration to ensure that the ACPI subsystem is active and that hotplug support reflects the new bounds checks.
  • If an immediate kernel upgrade is not possible, mitigate by disabling ACPI hotplug or using BIOS settings to inhibit dynamic IOAPIC table loading until a patched kernel is available.

Generated by OpenCVE AI on September 19, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths.
Title ACPI: processor: validate MADT IOAPIC entry bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:37.542Z

Reserved: 2026-09-16T12:21:13.874Z

Link: CVE-2026-92522

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:55.150

Modified: 2026-09-18T18:18:14.130

Link: CVE-2026-92522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer