---
id: CVE-2026-90191
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mailbox: riscv-sbi-mpxy: validate RPMI notification lengths

  The SBI return value controls how many bytes are copied from shared
  memory into the RPMI notification buffe…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mailbox: riscv-sbi-mpxy: validate RPMI notification lengths

  The SBI return value controls how many bytes are copied from shared
  memory into the RPMI notification buffe…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <
    cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b
  - >-
    Linux >= bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <
    c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76
  - >-
    Linux >= bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <
    11d5af151bcbe78f5a579e0faecd3be9cea0399a
  - Linux 6.18
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:45.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90191'
references:
  - url: 'https://git.kernel.org/stable/c/11d5af151bcbe78f5a579e0faecd3be9cea0399a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.0018
epssPercentile: 0.07881
ingestedAt: '2026-09-17T16:21:47.863Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mailbox: riscv-sbi-mpxy: validate RPMI notification lengths

The SBI return value controls how many bytes are copied from shared
memory into the RPMI notification buffer. It is not validated against
the negotiated shared-memory size before that copy. The event walker
also uses a reversed loop condition and can inspect a short event record.

Validate the complete notification length before copying it, iterate only
while a full event header remains, and stop when a declared event payload
extends beyond the copied notification data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
