From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8B9655803BC for ; Fri, 11 Sep 2026 19:52:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156368; cv=none; b=QwpqMf/l3IAipj/M1egahhrG6FByCnK2wBj1DETiaeAZB8RHdtMW8yobnz2EtnjHUBWq2E9Rpra/kEwoZeLPerddekJoEULUX6H0GRTl5ljb80OzHTJrUV8FimHmGGM/Sy4yJG7lRD9Uq/NXKeEs4EgOrOZkhFaNRwwatHAqHxQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156368; c=relaxed/simple; bh=JhmHTEr8Tmk7webTisqwU9erCi/yfJ9Dp56MqE6mp7I=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=D2tO5ypAj1whLE2SIHivi2MXnr5cegsaYmbY1q9bUAEMDJrnviFCntTqhUVyVVefU9NMwPTV5c3AEm2FmF8mtr/Liy1Yi3JA0zOOXnkzNoSEkUihnx66T/IBuCriBeJQz/bUlqb9m04AGPU9CdSExWMF1ygl+PjLNrftQN7yzNo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=v6J3o7ZZ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="v6J3o7ZZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 35D411F0089B; Fri, 11 Sep 2026 19:52:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156351; bh=EAWo48ReXEjLY+IePfF8Q4/vjGoIYVZmB3LYNzRIXiM=; h=From:To:Cc:Subject:Date:Reply-To; b=v6J3o7ZZ3RUUKTsblcHI2k5KRNvlQmWuiv+N9FFO0gq5bVm1G61WL/AJrmWONrOjW lZTsjaP5wfgV3Kl0+/LwfxwJphmacRif6fCxcATED+7HRIF4mzNefN4h/2mPKNmU28 2Bawi9hc3j3EshT2roHVkGZaYo56iko2GPD1IgD0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89489: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall Date: Fri, 11 Sep 2026 21:42:58 +0200 Message-ID: <2026091107-CVE-2026-89489-6c03@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3076; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=8SOYuN+E97mQDr7vmYVayfXvsu3LO8Gni/qPb5f1PV4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIoO7L/U0dX/SVmHtis78yiBmo1d2/knH+tTP62cf+ frFjFeuI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACby8yjD/IzFNp57Fnfv3bWW ndE369XX1gk1PgwLOntWcS4Tv/DKYqPXNoUvJ2xOvgzrBAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly. l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29 The pointers are not checked with access_ok(). The four memory accesses also have no exception table entries. A caller passes a kernel address as either pointer, and the syscall reads from and writes to it directly. This gives an unprivileged process a kernel read/write primitive. It overwrites kernel data such as the sys_call_table, gaining code execution in kernel context. Check both pointers before entering the critical section. Add fixups for the four memory accesses so faults on valid but unmapped user addresses return -EFAULT. [shorne@gmail.com: fix comment style] The Linux kernel CVE team has assigned CVE-2026-89489 to this issue. Affected and fixed versions =========================== Issue introduced in 3.1 with commit 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a and fixed in 6.12.109 with commit a520e8cac54fb403f3800125b606f55fcad42cb9 Issue introduced in 3.1 with commit 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a and fixed in 6.18.50 with commit d64a75369cd0f2ee79afcc9d9ca34a3890989379 Issue introduced in 3.1 with commit 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a and fixed in 7.2.4 with commit b53435c079c78f89f70a62dd5a322cca4e292b34 Issue introduced in 3.1 with commit 9d02a4283e9ce4e9ca11ff00615bdacdb0515a1a and fixed in 7.3-rc1 with commit 78004e9a87f240df03e2f73120d291763c32e0a7 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89489 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: arch/openrisc/kernel/entry.S Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a520e8cac54fb403f3800125b606f55fcad42cb9 https://git.kernel.org/stable/c/d64a75369cd0f2ee79afcc9d9ca34a3890989379 https://git.kernel.org/stable/c/b53435c079c78f89f70a62dd5a322cca4e292b34 https://git.kernel.org/stable/c/78004e9a87f240df03e2f73120d291763c32e0a7