Junglewise Threat Intelligence

CVE-2026-89459: Linux kernel s390 percpu MVIY instruction generation failure with older binutils

CVE-2026-89459 · Severity: high · CVSS 7 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's per-CPU operation macro (MVIY_PERCPU) fails to generate correct assembly instructions when compiled with GNU binutils versions prior to 2.39. This causes the interrupted per-CPU sequence to not be properly marked in lowcore memory, preventing exception handling from correctly repairing per-CPU address registers after CPU migration, which can lead to data corruption or system instability in multi-processor environments.

Technical details

The vulnerability is a code generation bug in the MVIY_PERCPU() macro introduced in commit a737737cdb9c. The macro uses __stringify() on arguments that are already C string literals, generating whitespace-separated quoted arguments in the assembler invocation. GNU as versions prior to binutils 2.39 strip whitespace between quoted macro arguments during input scrubbing, causing them to be parsed as a single malformed argument. The .ifc conditional in GEN_MVIY never matches, and while GNU as exits successfully with warnings, the mviy instruction is never emitted. This affects kernel versions from 4.9 onwards that use binutils 2.30 through 2.38. The fix removes the __stringify() calls and uses explicit comma separation in the assembler macro arguments, which is unambiguous for both GNU as and LLVM's integrated assembler. Patches are available in the Linux stable git tree.

Affected products

  • Linux Linux kernel 4.9.y through 6.x (affected on s390 architecture when compiled with binutils < 2.39)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89459 published
  • 2026-08-13: patched: Fix committed to Linux stable tree (commit 101782f8945a125044347312d74d488c05741c4a)
  • 2026-09-07: patched: Fix included in stable kernel release (commit 91770b08a120967077ae78600612f18bc5ee3caf)

References

Related threats