{"id":"CVE-2026-89489","title":"kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (CVE-2026-89489)","summary":"A flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to th…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-822","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T21:23:44+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89489.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89489.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89489"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532099"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89489"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89489"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89489.mbox"},{"url":"https://git.kernel.org/stable/c/bf310718c6fa6adeee06d207a55489546d860e2c"},{"url":"https://git.kernel.org/stable/c/497cba0b02e5555d99fe9ee1dc478af743ab7f7a"},{"url":"https://git.kernel.org/stable/c/1f2e92e499d863f81df1732af59b4a3559969193"},{"url":"https://git.kernel.org/stable/c/574ae2ac2b314aa33498cd2c28add106cbe644f2"},{"url":"https://git.kernel.org/stable/c/a520e8cac54fb403f3800125b606f55fcad42cb9"},{"url":"https://git.kernel.org/stable/c/d64a75369cd0f2ee79afcc9d9ca34a3890989379"},{"url":"https://git.kernel.org/stable/c/b53435c079c78f89f70a62dd5a322cca4e292b34"},{"url":"https://git.kernel.org/stable/c/78004e9a87f240df03e2f73120d291763c32e0a7"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00136,"epssPercentile":0.03394,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89489","body":"## Overview\n\nA flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to the syscall, gaining unauthorized read and write access to kernel memory. This vulnerability allows an attacker to overwrite critical kernel data, potentially leading to arbitrary code execution with elevated privileges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89489.json)\n\n**kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206952,"id":"CVE-2026-89489","ts":1789749715272,"field":"cvss","old":"7.8","new":"5.5"},{"seq":206951,"id":"CVE-2026-89489","ts":1789749715272,"field":"severity","old":"high","new":"medium"},{"seq":198009,"id":"CVE-2026-89489","ts":1789384321362,"field":"cvss","old":"7","new":"7.8"},{"seq":183786,"id":"CVE-2026-89489","ts":1789356677385,"field":"cvss","old":"7.8","new":"7"},{"seq":153276,"id":"CVE-2026-89489","ts":1789285349847,"field":"cvss","old":null,"new":"7.8"},{"seq":153275,"id":"CVE-2026-89489","ts":1789285349847,"field":"severity","old":"none","new":"high"},{"seq":147774,"id":"CVE-2026-89489","ts":1789270212237,"field":"cvss","old":null,"new":"7"},{"seq":147773,"id":"CVE-2026-89489","ts":1789270212237,"field":"severity","old":"none","new":"high"},{"seq":109532,"id":"CVE-2026-89489","ts":1789183732308,"field":"cvss","old":null,"new":"7"},{"seq":109531,"id":"CVE-2026-89489","ts":1789183732308,"field":"severity","old":"none","new":"high"}]}