Answer in brief
CVE-2026-89909 records a Unknown severity vulnerability in LoongArch: KVM: Free init resources if kvm_init() fails. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2bd6ac68726131da32ace9717aa63ff68cf6605c <6bbbd7b719233645a5c120557a9ca1422e6b7a48 || >=2bd6ac68726131da32ace9717aa63ff68cf6605c <6b78786ee7260d9818cf1d7a245b7a655ef83076 || >=2bd6ac68726131da32ace9717aa63ff68cf6605c <3bf6f5e2e1007d38a5f35bd37e94ab645a0c40bc || >=2bd6ac68726131da32ace9717aa63ff68cf6605c <f7a1064cce3b100b54780c68529176232d8eb01e | 6bbbd7b719233645a5c120557a9ca1422e6b7a48, 6b78786ee7260d9818cf1d7a245b7a655ef83076, 3bf6f5e2e1007d38a5f35bd37e94ab645a0c40bc, f7a1064cce3b100b54780c68529176232d8eb01e |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Free init resources if kvm_init() fails kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the perf callbacks, and then calls kvm_init(). If kvm_init() fails its result is returned directly, but since module_init() does not run the module_exit() stuff on failure, so kvm_loongarch_env_exit() is never called and those resources are leaked. So call kvm_loongarch_env_exit() when kvm_init() fails, matching the teardown-on-failure pattern used by riscv_kvm_init().
Quoted source text, attributed separately from HOL analysis.