From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7170B563FCE for ; Fri, 11 Sep 2026 19:57:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156671; cv=none; b=AEfI7/5qu24K89V6bEDJei3/g2l2H/LcKXmZQhUWZyWEwu9dHVRRrHQlYkcdT2CYw3IrzD3Yn/WIM174W/jlFM3Ab8yezOGGYV7+1og9JPJ4H5UR0fSOySmxfGlMCtGw8DpQRdIuuVLXL4JeGKzUxmoOAqq+vD8CBEqzboMMXxM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156671; c=relaxed/simple; bh=YFliXyDRxu3sHIcRAnv1uwDK7fNwgNVIJvChQi2hd8A=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=g0UygbgOLT4oOj5az0D6l2C06zIZp01oAVXiv41UtQZUTOMUBzSXz8dv87Xxcu1NWOPJ7wQxDDBViaJxh+WWsWbc3/jUycEm0MWc+1Xf/0LXI3WdlrTZeNEIP8CZAMf7DuhcLVHX2hPvfFYJ/+6V9KkqAgZ6uPv4VLbS11fpq9Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ClGBirh3; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ClGBirh3" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4EB511F0089D; Fri, 11 Sep 2026 19:57:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156657; bh=OSB9Qc0giPVgt0y9y1jADTaTqKmn0IFVywjABh0u0ys=; h=From:To:Cc:Subject:Date:Reply-To; b=ClGBirh3xtHwr+n9j8meiB65pm2EgPb1y/GNiqsUQ1wJUGSruE856z0NNKB+FLdbX JrY6CGrvT8erfAfM+dAvzgP1CTzZYZG6nDfGlroqVJgL0X4WCd+Tx4CWNVOeOm4Y5x EhM+ir+D37E4E7FUi194l2u769pYYw8UZT236Od8= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89556: module: validate string table section types Date: Fri, 11 Sep 2026 21:44:05 +0200 Message-ID: <2026091122-CVE-2026-89556-193f@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2362; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=D3r50GJIQNQE3Gih9XoCER3iaVmWW4J95bTSChX3Ryk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIpMuGnL2WN4zTWZk3DxpcsuKB1Y+F1wXHN/Qqi93Q yEilzmwI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACbyZBvDPMW1evHG210uOF0z fFkWGvCQMUy/kmGuWGP1E/ebv1493PxPX6yJz861/Qs/AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: module: validate string table section types In elf_validity_cache_sechdrs, section sizes and offsets are validated, unless the section type is SHT_NULL or SHT_NOBITS. Later, elf_validity_cache_secstrings and elf_validity_cache_index_str access the section name table (.shstrtab) and symbol string table (.strtab) headers without first ensuring that their types are SHT_STRTAB. If a section type is SHT_NULL or SHT_NOBITS, sh_offset has not been validated and may reference out-of-bounds memory when dereferenced in elf_validity_cache_secstrings or elf_validity_cache_strtab. Validate that both string section headers are of type SHT_STRTAB before caching them. The Linux kernel CVE team has assigned CVE-2026-89556 to this issue. Affected and fixed versions =========================== Fixed in 6.18.50 with commit 50d0aa7d25ba4bc3606f150cd69755068e79f97f Fixed in 7.2.4 with commit e4496dda2c6d0acf7ba5fbce14a2723a8935ceee Fixed in 7.3-rc1 with commit 9a5ff45689329835f874cefe5174e577d141d423 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89556 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/module/main.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/50d0aa7d25ba4bc3606f150cd69755068e79f97f https://git.kernel.org/stable/c/e4496dda2c6d0acf7ba5fbce14a2723a8935ceee https://git.kernel.org/stable/c/9a5ff45689329835f874cefe5174e577d141d423