{"id":"CVE-2026-89826","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: harden firmware build-info bounds checks\n\npanthor_fw_read_build_info() checks whether the metadata range fits in the\nfirmware image with hdr.meta_start + h…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: harden firmware build-info bounds checks\n\npanthor_fw_read_build_info() checks whether the metadata range fits in the\nfirmware image with hdr.meta_start + h…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 2718d91816eeed03c09c8abe872e45f59078768c < 5516f1acfd07564361cf306cc90a8e513df0f096","Linux >= 2718d91816eeed03c09c8abe872e45f59078768c < 6ae19dce3e8c13ae73590b3f4311abe9f96bbae8","Linux >= 2718d91816eeed03c09c8abe872e45f59078768c < 8321b093fa6c297b80586460ce6914d9655df170","Linux 6.10"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:11.553","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89826","references":[{"url":"https://git.kernel.org/stable/c/5516f1acfd07564361cf306cc90a8e513df0f096","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ae19dce3e8c13ae73590b3f4311abe9f96bbae8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8321b093fa6c297b80586460ce6914d9655df170","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:54.002Z","epss":0.00164,"epssPercentile":0.04932,"slug":"CVE-2026-89826","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: harden firmware build-info bounds checks\n\npanthor_fw_read_build_info() checks whether the metadata range fits in the\nfirmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so\nthe addition can wrap and let an out-of-bounds range pass validation.\n\nThe function also reads the \"git_sha: \" prefix without first checking that\nthe metadata is long enough, and meta_size == 0 can underflow the NULL\nterminator index.\n\nUse subtraction-based bounds checking and reject metadata that is too short\nto contain the expected prefix and trailing NULL byte.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205210,"id":"CVE-2026-89826","ts":1789570705742,"field":"cvss","old":null,"new":"7.1"},{"seq":205209,"id":"CVE-2026-89826","ts":1789570705742,"field":"severity","old":"none","new":"high"}]}