CVE-2026-89513Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) component for RISC-V architectures. A malicious guest operating system could exploit an integer overflow vulnerability by providing a crafted number of Performance M…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 7
none → high
— → 7
none → high
— → 8.8
none → high
8.8 → 7
7 → 8.8
8.8 → 7
Last analysed / modified upstream
7 → 5.5
high → medium
A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) component for RISC-V architectures. A malicious guest operating system could exploit an integer overflow vulnerability by providing a crafted number of Performance Monitoring Unit (PMU) events during the SBI PMU EVENT_GET_INFO call. This leads to KVM allocating insufficient memory, resulting in out-of-bounds reads and writes. This memory corruption could allow a malicious guest to cause a denial of service (DoS) or potentially escalate privileges on the host system.
kernel: RISC-V: KVM: Fix PMU event info array size overflow — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89436Medium· 5.5kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] (CVE-2026-89436)
CVE-2026-89610Medium· 5.5kernel: ntfs: verify run length exceeding volume boundary (CVE-2026-89610)
CVE-2026-89611Medium· 5.5kernel: ntfs: validate non-resident attribute offsets (CVE-2026-89611)
CVE-2026-89612Medium· 5.5kernel: ntfs: reject invalid MFT LCNs from boot sector (CVE-2026-89612)
CVE-2026-89748Medium· 6.1kernel: Linux kernel: Ring buffer corruption in tracing due to retry exhaustion (CVE-2026-89748)
CVE-2026-89471Medium· 5.5kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count (CVE-2026-89471)