From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E01C95867C6 for ; Fri, 11 Sep 2026 19:56:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156572; cv=none; b=kItOEsDGkMjLbSRTeS2snPsJ3UTXEeTay11gn2dWvLZ3+/zAC5PNsMFb1dkAbBshi+eQ5x4Zen0PMepioUKjxEtPVhXeKog3g5sb8BDU7c5vnmdNoThMOzwVW0P5ug0eZinC9qc/c0lO9fonhGt9MQDyuLM/s7n/wcCMVBecWIM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156572; c=relaxed/simple; bh=qZuyBdD/5DcaxteFYHd++WeYXFwS2PIL5Wc+HbgyCaw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=p49ic11Z41fl/1JJOlK4mM/vRQq9+qOtb3RUdyOgVcil6mSkVIzUiWhKGXPpk7mRRs5JM9AmkqsV+Gwp6J3J8Ruj+nHf2ALWTMstxLbJ4vzw/tpfXM9oHJQROt3t8g4kCKfn3TtQ1Lnnos6t+ack2F1PVbd8scHNieAYZ/SddrE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=INAGaMsh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="INAGaMsh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 949861F0089D; Fri, 11 Sep 2026 19:55:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156559; bh=GyalSEqiG7kLbCTMQlFqCzIxddpV6i0dLt99tQGjlrY=; h=From:To:Cc:Subject:Date:Reply-To; b=INAGaMshvHZKQiyKSCM1hjYRCc67fAbIrFZv3gz238tzs7ii+Cr5ktYvHvm55bRya dm7WGnaJdPIXdUHUGakSN4ajzvyk4RBL5oNycbyfnnxUU2sTLe/W8DV31iFMUbbSGN GnPHLE7rLlwgC33sFVaDhay68gc9S3lcLFpFIe84= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89513: RISC-V: KVM: Fix PMU event info array size overflow Date: Fri, 11 Sep 2026 21:43:22 +0200 Message-ID: <2026091112-CVE-2026-89513-e5c1@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3183; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=iLJiMimVIVNhGCb+gMEpt4Fe6dqLMGMIsAyDkFhS/gk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIiN3b5k6gXPyFJUz7JEfVyqUpiR81Vrdzsy94tnKa ptigdsuHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRGzcZ5pfrKF7MfXvidFHq 2stRV7udT+ZcY2SYXywfZzG99uzD3k/c3mySBgrv/GpOAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflow SBI PMU EVENT_GET_INFO stores guest-controlled num_events * sizeof(*einfo) in a 32-bit integer. On RV64, num_events = 0x10000001 makes 0x100000010 truncate to 16. KVM then allocates one entry but loops over the original num_events, causing out-of-bounds reads and writes. A nested guest triggered: BUG: KASAN: slab-out-of-bounds in kvm_riscv_vcpu_pmu_event_info+0xa4/0x142 Read of size 4 at addr ff600000074d46b0 by task init/1 Call Trace: [] kvm_riscv_vcpu_pmu_event_info+0xa4/0x142 [] kvm_sbi_ext_pmu_handler+0xca/0x268 [] kvm_riscv_vcpu_sbi_ecall+0xec/0x1e6 [] kvm_riscv_vcpu_exit+0x48c/0x540 [] kvm_arch_vcpu_ioctl_run+0x37e/0xc80 Allocated by task 1: __kmalloc_noprof+0x19e/0x4b0 kvm_riscv_vcpu_pmu_event_info+0x72/0x142 kvm_sbi_ext_pmu_handler+0xca/0x268 kvm_riscv_vcpu_sbi_ecall+0xec/0x1e6 kvm_riscv_vcpu_exit+0x48c/0x540 kvm_arch_vcpu_ioctl_run+0x37e/0xc80 The buggy address is located 0 bytes to the right of allocated 16-byte region [ff600000074d46a0, ff600000074d46b0) Store the shared-memory size in size_t and reject multiplication overflow. Allocate the guest-driven array with GFP_KERNEL_ACCOUNT so it is charged to kmemcg, and use __GFP_NOWARN to suppress allocation failure warnings. Use kvcalloc() to allow vmalloc fallback and an unsigned long loop index to match num_events. The Linux kernel CVE team has assigned CVE-2026-89513 to this issue. Affected and fixed versions =========================== Issue introduced in 6.18 with commit e309fd113b9f6c34672a487be08fecb7e12e7e29 and fixed in 7.2.4 with commit 82088f88c96b99c27a974d09b02c2b133262fadf Issue introduced in 6.18 with commit e309fd113b9f6c34672a487be08fecb7e12e7e29 and fixed in 7.3-rc1 with commit 735bc20c24187ca419c9d5e63860a54b91be34bd Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89513 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: arch/riscv/kvm/vcpu_pmu.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/82088f88c96b99c27a974d09b02c2b133262fadf https://git.kernel.org/stable/c/735bc20c24187ca419c9d5e63860a54b91be34bd