{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "12a7d2cb811dd8a884dea088a2701fcb8d00136e"
            },
            {
              "fixed": "c9ee2770eb95ba316a56d776b2b66666b70c194b"
            },
            {
              "fixed": "5b032e1dda486ca41d10536bd195bd8a559af1e2"
            },
            {
              "fixed": "82d4afadb02fb4d7d7bb9230900904c10e49ec87"
            },
            {
              "fixed": "124e2dbabe460c2a6e7440f4ad8af560131295c9"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.4.0"
            },
            {
              "fixed": "6.12.109"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.50"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89438.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate logical CPU id and clos id\n\nValidate max CLOS ID and logical CPU ID for core power feature.\nReject any clos level or logical CPU number greater than the\nsupported maximum. These are used to calculate MMIO offset.",
  "id": "CVE-2026-89438",
  "modified": "2026-09-13T03:30:39.983698489Z",
  "published": "2026-09-11T19:43:08.077Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89438.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89438"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "platform/x86: ISST: Validate logical CPU id and clos id"
}