Junglewise Threat Intelligence

CVE-2026-89571: Linux kernel CXL out-of-bounds read in fwctl command handling

CVE-2026-89571 · Severity: high · CVSS 7.1 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's CXL (Compute Express Link) driver handles firmware control commands used to communicate with CXL memory devices. A flaw in input validation allows an attacker to read memory beyond the allocated input buffer and send it to the device, potentially causing a kernel crash or information disclosure.

Technical details

The vulnerability is an out-of-bounds read in the cxl/features module, specifically in the cxlctl_fw_rpc() function. The fwctl_cmd_rpc() function allocates a buffer of size cmd->in_len and copies user input into it, then passes this buffer and in_len to the CXL callback. However, cxlctl_fw_rpc() does not validate that the user-controlled op_size field fits within the copied buffer. An attacker can specify a large op_size value that exceeds the available buffer, causing subsequent memcpy() operations to read beyond the allocated boundary. The out-of-bounds data is then placed in the mailbox payload. A sufficiently large op_size can walk into unmapped kernel memory and trigger an oops. The fix adds bounds checking at the dispatch point to ensure that the fixed header plus op_size does not exceed in_len before reading the opcode or processing the command.

Affected products

  • Linux Linux kernel Versions with CXL feature command support (introduced in commit eb5dfcb9e36d)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89571 published
  • 2026-06-20: patched: Fix committed upstream by Zhenhao Wan
  • 2026-09-07: patched: Fix merged into stable kernel releases

References

Related threats