{"id":"CVE-2026-89438","title":"kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)","summary":"A flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core powe…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:34:48+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89438.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89438.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89438"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532236"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89438"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89438"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89438.mbox"},{"url":"https://git.kernel.org/stable/c/0d601126c7afda9bb94dfecc8b2c0a16f20d76cb"},{"url":"https://git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b"},{"url":"https://git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2"},{"url":"https://git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87"},{"url":"https://git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.002,"epssPercentile":0.10108,"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-89438","body":"## Overview\n\nA flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core power feature. A local attacker could exploit this by providing invalid input, which might lead to incorrect calculations for memory-mapped I/O (MMIO) offsets. This could result in memory corruption, potentially allowing for system instability, unauthorized information access, or an increase in privileges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89438.json)\n\n**kernel: platform/x86: ISST: Validate logical CPU id and clos id** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204117,"id":"CVE-2026-89438","ts":1789490231734,"field":"cvss","old":null,"new":"5.5"},{"seq":204116,"id":"CVE-2026-89438","ts":1789490231734,"field":"severity","old":"none","new":"medium"},{"seq":147508,"id":"CVE-2026-89438","ts":1789270211183,"field":"cvss","old":null,"new":"4.7"},{"seq":147507,"id":"CVE-2026-89438","ts":1789270211183,"field":"severity","old":"none","new":"medium"},{"seq":109266,"id":"CVE-2026-89438","ts":1789183731205,"field":"cvss","old":null,"new":"4.7"},{"seq":109265,"id":"CVE-2026-89438","ts":1789183731205,"field":"severity","old":"none","new":"medium"}]}