Junglewise Threat Intelligence

CVE-2026-89730: Linux kernel altera-cvp out-of-bounds read in trailing byte write

CVE-2026-89730 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Altera CvP FPGA driver contains a memory safety bug in its firmware image upload path. When processing the final 1-3 bytes of an FPGA bitstream image, the driver reads beyond the input buffer boundary if the buffer ends at a page or scatter-list boundary, potentially causing a kernel crash (denial of service). This affects systems using Altera FPGA devices with the CvP (Configuration via Protocol) interface.

Technical details

The vulnerability is a classic out-of-bounds read in the altera_cvp_send_block() function within drivers/fpga/altera-cvp.c. The vulnerable code dereferences a u32 pointer to process trailing bytes (1-3 bytes remaining after 4-byte word processing), even when fewer than 4 bytes remain in the input buffer. If the buffer ends at a memory boundary (page boundary or end of a scatter-list segment), this causes a read past valid image data. The fix copies the remaining bytes into a zero-initialized u32 buffer using memcpy() before writing, ensuring only valid bytes are read from the source buffer. No user interaction or authentication is required; the bug is triggered during normal FPGA firmware upload operations.

Affected products

  • Linux Linux kernel Multiple versions (see stable branches linux-4.9.y through linux-7.2.y and rolling-stable)

Timeline

  • 2026-09-11: disclosed
  • 2026-09-14: patched: Fix committed to stable kernel branches by Greg Kroah-Hartman

References

Related threats