CVE-2026-89448
CRITICAL
Published Sep 11, 2026
Modified Sep 14, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu().
Is your site exposed to CVE-2026-89448?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
9.3
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — Exploit Prediction
0.0014
Probability of exploitation
0.04%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/45705a6bfdb283f7b3b509010fd617b72f942537
https://git.kernel.org/stable/c/579eb867d3da63f3b5e32f235925e1daa7ec70d0
https://git.kernel.org/stable/c/607432b2618b61df81134be0ef2562b8300c1216
https://git.kernel.org/stable/c/87bc611c6c98a41c00feb7b06b0c297dd141a2ae
https://git.kernel.org/stable/c/aaeb81241e802c86be69394f72d49fde3f861fbb
Frequently Asked Questions
What is CVE-2026-89448? +
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Force requesting ACS when tboot is enabled
Currently the conditions of requesting ACS in detect_intel_iommu()
don't include tboot, leading to a possible misconfiguration with ACS
disabled (e.g. due to user opts) while iommu is later forced on by
tboot_force_iommu().
Fix it by checking tboot in detect_intel_iommu(). It has a CVSS v3.1 base score of 9.3 (CRITICAL).
How severe is CVE-2026-89448? +
CVE-2026-89448 has a CVSS v3.1 score of 9.3 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately. The EPSS score is 0.0014, placing it in the 0th percentile for exploitation probability.
How do I check if I'm vulnerable to CVE-2026-89448? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.