From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A463058122A for ; Fri, 11 Sep 2026 19:50:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156213; cv=none; b=Fg/Ct/7Lkl3s3zq2R+alO6YoxsdJBZFv8V8/3w5yT3NMUzHuXPXc1mNIJljaXdh8D9MxM7IRf8d1TUbBKHORqLg9ZdJAJOmvZlEaJMGpnYye8l2bf3+eNSQWfjjK1a7cu976/Qnq7HmO5r8t4WXVVfCPEd0sJK68UiL4o3qR57E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156213; c=relaxed/simple; bh=X9feJJM/SFY6oCfWokoU5fSb1V1lBCcFBfX+9WZMzgU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=EUB2+alMEuNBqjk94HPfeOR60AYfXK9WdA4axB0QlHIpPKUNAkY8gPGg04abkjzgOVVyy+5j7LQTSOQFCXvpq6F09XMFI069RpFyagmLhRRo293lBElIVEEj/r/lBmaSa1kCadwPuL0lCBWWrsJ1QfahQcoomJ/6FZYx1LTptkw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=olZx2Jz2; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="olZx2Jz2" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8E1431F00899; Fri, 11 Sep 2026 19:49:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156199; bh=JmmIzdpt6GBOKn0u44sNETjl7OShkH79r3Jc0Lb3hKw=; h=From:To:Cc:Subject:Date:Reply-To; b=olZx2Jz2v0qQpjUXFTDMGHwxCcPzuMpHrmMnt8Ti+ADQ1QOcCOofwgzKqgC7mCaH7 jybxO+K3T1YccoxOVXXJKrF2w6HALIEtw7xk/8dudTfmXZ9OKNkJ5pDEH8bVLq/NUl /SQnUSEfL4sf7ndhaMBLLqAlXB+1CilLeItlpjSE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89436: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] Date: Fri, 11 Sep 2026 21:42:05 +0200 Message-ID: <2026091155-CVE-2026-89436-8035@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3339; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=18BA8Hzi+P/wqdk3GiX/zevJSMQT5M0H9xNBQPklhWE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIt23BZS4fKnKt7jZcEhs+oPX6f7T9578OOOsDf/SJ Ynq73rjOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAinyYzLJhn3X5o6o2woucx E6q5dOz3ZUw9kc0wh9ey8LnibhPjhONKj2at5m9yzzr6HgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] acpi_pcc_retrieve_biosdata() rejects SINF packages only when pcc->num_sifr is strictly less than hkey->package.count, then unconditionally writes a trailing sentinel at pcc->sinf[hkey->package.count]. But pcc->sinf[] is allocated with exactly pcc->num_sifr elements (valid indices 0..num_sifr-1), so that write needs num_sifr strictly greater than package.count to stay in bounds -- num_sifr == package.count passes the existing check but still overflows by one element. This is exactly the case probe()'s existing num_sifr++ workaround ("Some DSDT-s have an off-by-one bug where the SINF package count is one higher than the SQTY reported value") is written to accommodate: when a DSDT's SINF package count equals SQTY+1, the workaround makes num_sifr equal to package.count, which is precisely the boundary that overflows here. Found via UBSan (array-index-out-of-bounds) on hardware where HKEY.SQTY returns 37 and HKEY.SINF()'s package has 38 elements: num_sifr becomes 38 after the += 1 workaround, the loop correctly fills indices 0..37, and the sentinel write then targets index 38, one past the end -- a silent 4-byte heap overflow on kernels without CONFIG_UBSAN. Tightening the rejection check to num_sifr <= package.count would avoid the overflow but breaks probe() entirely on exactly this hardware, since num_sifr == package.count is the case the off-by-one workaround exists to support. Nothing else in the driver reads this sentinel value back, so simply skip the write when there is no room for it instead. The Linux kernel CVE team has assigned CVE-2026-89436 to this issue. Affected and fixed versions =========================== Issue introduced in 7.2 with commit a3d0dbd18ce908292607bb6cf37c978ece8a33d4 and fixed in 7.2.4 with commit a93df956ee4d903735b6d395362c839cb1dc07e3 Issue introduced in 7.2 with commit a3d0dbd18ce908292607bb6cf37c978ece8a33d4 and fixed in 7.3-rc1 with commit 329f10d8be193bf36af124e00b9dd6644cd71724 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89436 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/platform/x86/panasonic-laptop.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a93df956ee4d903735b6d395362c839cb1dc07e3 https://git.kernel.org/stable/c/329f10d8be193bf36af124e00b9dd6644cd71724