CVE-2026-89438Medium· 5.5▾ SunlitA flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core powe…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.7
none → medium
— → 4.7
none → medium
Last analysed / modified upstream
— → 5.5
none → medium
A flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core power feature. A local attacker could exploit this by providing invalid input, which might lead to incorrect calculations for memory-mapped I/O (MMIO) offsets. This could result in memory corruption, potentially allowing for system instability, unauthorized information access, or an increase in privileges.
kernel: platform/x86: ISST: Validate logical CPU id and clos id — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80986High· 7.0kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
CVE-2026-80951High· 7.0kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)
CVE-2026-81000High· 7.8kernel: net: tun: bound receive headroom (CVE-2026-81000)
CVE-2026-81002High· 7.0kernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
CVE-2026-89482High· 7.0kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (CVE-2026-89482)