{"id":"CVE-2026-89594","title":"kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device (CVE-2026-89594)","summary":"A flaw was found in the Linux kernel's OMAP SSI driver. The driver uses a synthetic HSI controller device that does not properly initialize its Direct Memory Access (DMA) mask. This oversight can lead to the driver crashing or triggering w…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-909","vendor":"Red Hat","product":"Linux","affected":["Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < 6a5426f56de98faf7886702f8720828bf346a48f","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < a4beb841f84e0e6ad5ff3d114f43ad30165572dd","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < 9ecef057b7a7f165ce66eaf07cb4cf85d10ed9c7","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < 9963a65be2befff82b5f5a7cfcd7ac4aca081c0b","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < e8d47e309c704df95816e7442f05947424d8b33f","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < 4e019e5e247bfe877fdf288f2d6ec1b4c850c7c6","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < fbffbfdae55954213fea99c5c9856c48dc705019","Linux >= f959dcd6ddfd29235030e8026471ac1b022ad2b0 < e81250ec6b69248b00d38c523dc6a13efaf38aab","Linux 4e57482e8440fac7137832629109730ea4b267aa","Linux >= 5.9.2 < 5.10","Linux 5.10"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T05:47:04+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89594.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89594.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89594"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532500"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89594"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89594"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89594.mbox"},{"url":"https://git.kernel.org/stable/c/6a5426f56de98faf7886702f8720828bf346a48f"},{"url":"https://git.kernel.org/stable/c/a4beb841f84e0e6ad5ff3d114f43ad30165572dd"},{"url":"https://git.kernel.org/stable/c/9ecef057b7a7f165ce66eaf07cb4cf85d10ed9c7"},{"url":"https://git.kernel.org/stable/c/9963a65be2befff82b5f5a7cfcd7ac4aca081c0b"},{"url":"https://git.kernel.org/stable/c/e8d47e309c704df95816e7442f05947424d8b33f"},{"url":"https://git.kernel.org/stable/c/4e019e5e247bfe877fdf288f2d6ec1b4c850c7c6"},{"url":"https://git.kernel.org/stable/c/fbffbfdae55954213fea99c5c9856c48dc705019"},{"url":"https://git.kernel.org/stable/c/e81250ec6b69248b00d38c523dc6a13efaf38aab"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00164,"epssPercentile":0.06024,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89594","body":"## Overview\n\nA flaw was found in the Linux kernel's OMAP SSI driver. The driver uses a synthetic HSI controller device that does not properly initialize its Direct Memory Access (DMA) mask. This oversight can lead to the driver crashing or triggering warnings when attempting DMA mapping operations, potentially causing a Denial of Service (DoS) condition.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89594.json)\n\n**kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203955,"id":"CVE-2026-89594","ts":1789490230785,"field":"cvss","old":"7.8","new":"5.5"},{"seq":203954,"id":"CVE-2026-89594","ts":1789490230785,"field":"severity","old":"high","new":"medium"},{"seq":197890,"id":"CVE-2026-89594","ts":1789384320829,"field":"cvss","old":"4.1","new":"7.8"},{"seq":197889,"id":"CVE-2026-89594","ts":1789384320829,"field":"severity","old":"medium","new":"high"},{"seq":183437,"id":"CVE-2026-89594","ts":1789356675365,"field":"cvss","old":"7.8","new":"4.1"},{"seq":183436,"id":"CVE-2026-89594","ts":1789356675365,"field":"severity","old":"high","new":"medium"},{"seq":153412,"id":"CVE-2026-89594","ts":1789285350409,"field":"cvss","old":null,"new":"7.8"},{"seq":153411,"id":"CVE-2026-89594","ts":1789285350409,"field":"severity","old":"none","new":"high"},{"seq":147099,"id":"CVE-2026-89594","ts":1789270195165,"field":"cvss","old":null,"new":"4.1"},{"seq":147098,"id":"CVE-2026-89594","ts":1789270195165,"field":"severity","old":"none","new":"medium"},{"seq":108850,"id":"CVE-2026-89594","ts":1789183729248,"field":"cvss","old":null,"new":"4.1"},{"seq":108849,"id":"CVE-2026-89594","ts":1789183729248,"field":"severity","old":"none","new":"medium"}]}