CVE-2026-89443: platform/x86: ISST: Validate level in perf mask ioctls

Published Sep 11, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: ISST: Validate level in perf mask ioctls

isstifgetperflevelmask() and isstifgetbasefreqmask() use the user-provided level as an index into perflevels[] via readpplevelinfo() and readbflevelinfo(), but neither helper validates it first.

The adjacent level-info helpers reject levels above maxlevel before reading the same per-level register block. Add the same bounds checks to the mask helpers, and reject disabled SST-PP levels in isstifgetperflevelmask() to match isstifgetperflevelinfo().

This prevents out-of-bounds reads from the per-level offset table on invalid ioctl input.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 11, 2026
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description

Frequently Asked Questions

1

What access would an attacker need to trigger this issue?

An attacker would need to supply an invalid level value through the affected ISST performance-mask ioctl interface. The vulnerability is triggered by user-controlled ioctl input being used as an unchecked index.

2

Which systems are exposed?

Exposure is limited to Linux systems using the platform/x86 ISST interface and the affected performance-mask ioctls. The provided information does not identify specific processor models, kernel versions, or default enablement conditions.

3

What behavior indicates an attempted or successful trigger?

The issue involves invalid ioctl level values causing out-of-bounds reads from a per-level offset table. The provided information does not specify logs, error messages, crashes, or other observable indicators.

4

What mitigation is available if an update cannot be applied immediately?

Restrict access to the affected ISST ioctl interface so untrusted users cannot submit ioctl requests. The vulnerability depends on user-provided invalid level input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203