Answer in brief
CVE-2026-89731 records a Unknown severity vulnerability in cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab <8bd3523df1319edc61cd391e695c84a4618516df || >=6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab <8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced || >=6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab <29458e62d0829cbc99435f3e44fd560f9bbf1da7 | 8bd3523df1319edc61cd391e695c84a4618516df, 8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced, 29458e62d0829cbc99435f3e44fd560f9bbf1da7 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block. The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read. The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability. Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.
Quoted source text, attributed separately from HOL analysis.