Answer in brief
CVE-2026-89442 records a Unknown severity vulnerability in platform/x86: ISST: Validate socket ID in clos_assoc ioctl. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=12a7d2cb811dd8a884dea088a2701fcb8d00136e <0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 || >=12a7d2cb811dd8a884dea088a2701fcb8d00136e <82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca || >=12a7d2cb811dd8a884dea088a2701fcb8d00136e <207b4dc6eb100141b122b2602504a1429a4b6558 || >=12a7d2cb811dd8a884dea088a2701fcb8d00136e <a89f07db0cb95c54dac4a8406c79a04e44a73c3c | 0d90ab5f80e19cddfeb0c9fab47a1f34aa932075, 82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca, 207b4dc6eb100141b122b2602504a1429a4b6558, a89f07db0cb95c54dac4a8406c79a04e44a73c3c |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with topology_max_packages() entries, so the valid index range is [0, topology_max_packages()). The '>' comparison lets socket_id == topology_max_packages() pass and index one entry past the array. In addition, isst_common.sst_inst[socket_id] is NULL for an in-range package that has no bound TPMI SST instance, and the pointer is used without a NULL check. Both the out-of-bounds entry and the NULL pointer are then dereferenced by map_partition_power_domain_id() and the following power_domain_info access. Reject socket_id >= topology_max_packages() and a NULL sst_inst, matching the checks already performed by get_instance().
Quoted source text, attributed separately from HOL analysis.