Executive brief
The Intel Speed Select Technology (ISST) platform driver in Linux contains a memory validation bug in its ioctl handler. An unprivileged local user can supply an invalid socket ID to trigger an out-of-bounds array access or null pointer dereference, potentially crashing the system or causing undefined behavior on systems with TPMI-based speed-select support.
Technical details
The isst_if_clos_assoc() function in the platform/x86 Intel speed-select driver validates user-supplied socket IDs using an off-by-one comparison ('socket_id > topology_max_packages()' instead of '>='), allowing socket_id equal to topology_max_packages() to pass validation. The sst_inst array is allocated with exactly topology_max_packages() entries, so valid indices are [0, topology_max_packages()). Additionally, the code dereferences sst_inst[socket_id] without checking for NULL pointers, which can occur for in-range packages lacking a bound TPMI SST instance. Both conditions allow out-of-bounds access or null pointer dereference in map_partition_power_domain_id() and subsequent power_domain_info access. The fix adds proper bounds checking (socket_id >= topology_max_packages()) and a NULL pointer check before dereferencing sst_inst. Local user interaction is required to invoke the ioctl.
Affected products
- Linux Linux kernel Affected in multiple stable series; patched in commit 0d90ab5f80e19cddfeb0c9fab47a1f34aa932075
Timeline
- 2026-09-11: disclosed: CVE-2026-89442 published
- 2026-09-07: patched: Fix committed to stable kernel trees