{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  RISC-V: KVM: Fix PMU event info array size overflow  SBI PMU EVENT_GET_INFO stores guest-controlled num_events * sizeof(*einfo) in a 32-bit integer. On RV64, num_events = 0x10000001 makes 0x100000010 truncate to 16. KVM then allocates one entry but loops over the original num_events, causing out-of-bounds reads and writes. A nested guest triggered:  BUG: KASAN: slab-out-of-bounds in kvm_riscv_vcpu_pmu_event_info+0xa4/0x142 Read of size 4 at addr ff600000074d46b0 by task init/1 Call Trace: [\u003cffffffff8006471c\u003e] kvm_riscv_vcpu_pmu_event_info+0xa4/0x142 [\u003cffffffff800690c0\u003e] kvm_sbi_ext_pmu_handler+0xca/0x268 [\u003cffffffff8006779e\u003e] kvm_riscv_vcpu_sbi_ecall+0xec/0x1e6 [\u003cffffffff8006008c\u003e] kvm_riscv_vcpu_exit+0x48c/0x540 [\u003cffffffff8005ea0a\u003e] kvm_arch_vcpu_ioctl_run+0x37e/0xc80 Allocated by task 1:  __kmalloc_noprof+0x19e/0x4b0  kvm_riscv_vcpu_pmu_event_info+0x72/0x142  kvm_sbi_ext_pmu_handler+0xca/0x268  kvm_riscv_vcpu_sbi_ecall+0xec/0x1e6  kvm_riscv_vcpu_exit+0x48c/0x540  kvm_arch_vcpu_ioctl_run+0x37e/0xc80 The buggy address is located 0 bytes to the right of  allocated 16-byte region [ff600000074d46a0, ff600000074d46b0)  Store the shared-memory size in size_t and reject multiplication overflow. Allocate the guest-driven array with GFP_KERNEL_ACCOUNT so it is charged to kmemcg, and use __GFP_NOWARN to suppress allocation failure warnings. Use kvcalloc() to allow vmalloc fallback and an unsigned long loop index to match num_events.",
  "id": "DEBIAN-CVE-2026-89513",
  "modified": "2026-09-14T08:47:47.489755640Z",
  "published": "2026-09-11T20:19:33.787Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89513"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89513"
  ]
}