CVE-2026-89730

Updated on 11 Sep 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write

The trailing byte path in altera_cvp_send_block() dereferences a u32 pointer even when only 1-3 bytes remain in the input buffer. If the buffer ends at a page or scatterlist boundary, this can read past the valid image data and fault.

Copy the remaining bytes into a zero-initialized u32 before writing the final word so only valid bytes are read from the input buffer.

Details

Affected packages:
linux @ 4.19.0 (+3 more)

Fixes