CVE-2026-90191: mailbox: riscv-sbi-mpxy: validate RPMI notification lengths
In the Linux kernel, the following vulnerability has been resolved:
mailbox: riscv-sbi-mpxy: validate RPMI notification lengths
The SBI return value controls how many bytes are copied from shared memory into the RPMI notification buffer. It is not validated against the negotiated shared-memory size before that copy. The event walker also uses a reversed loop condition and can inspect a short event record.
Validate the complete notification length before copying it, iterate only while a full event header remains, and stop when a declared event payload extends beyond the copied notification data.
Affected Software
Event History
Frequently Asked Questions
Which deployments are relevant to this issue?
The issue is specific to the Linux kernel mailbox riscv-sbi-mpxy path when handling RPMI notifications. The provided data does not indicate impact on other kernel subsystems or products.
Can affected kernel versions be determined from this record?
No affected or fixed kernel version numbers are provided. The record includes stable-tree commit references, but does not map them to release versions.