CVE-2026-89438
Published Sep 11, 2026
Modified Sep 14, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clos id Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are used to calculate MMIO offset.
Is your site exposed to CVE-2026-89438?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0020
Probability of exploitation
0.10%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/0d601126c7afda9bb94dfecc8b2c0a16f20d76cb
https://git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9
https://git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2
https://git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87
https://git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b
Frequently Asked Questions
What is CVE-2026-89438? +
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: ISST: Validate logical CPU id and clos id
Validate max CLOS ID and logical CPU ID for core power feature.
Reject any clos level or logical CPU number greater than the
supported maximum. These are used to calculate MMIO offset.
How do I check if I'm vulnerable to CVE-2026-89438? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.