CVE-2026-89751

UnknownEPSS 0.17%

Last modified

CVE-2026-89751 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use: u64 mask = GENMASK(BITS_PER_BYTE * size, 0); GENMASK(h, l) includes bit h. For size=1 (INB), this produces GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8 bits). EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use: u64 mask = GENMASK(BITS_PER_BYTE * size, 0); GENMASK(h, l) includes bit h. For size=1 (INB), this produces GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8 bits). The mask is one bit too wide for all I/O sizes. Fix the mask calculation.

Metrics

EPSS Probability
0.17%

6.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 03149948832a078f759022ed5b92e722d8d23c26, < c6875423ad849ac234ab9812eb72f37ff8a490b4; >= 03149948832a078f759022ed5b92e722d8d23c26, < 220011fe95fc78b2bc2d7d43893bc73957a5c811; >= 03149948832a078f759022ed5b92e722d8d23c26, < 222b7005e4519f633b4cd666226256abbab46a1a; >= 03149948832a078f759022ed5b92e722d8d23c26, < c4a22154870813d10aa0b4c734a574c726f9d4b0; >= 03149948832a078f759022ed5b92e722d8d23c26, < bb45f705c4440dd3c689328319b88dd28770bbb8; >= 03149948832a078f759022ed5b92e722d8d23c26, < 0f63e656b1c679d32ac595de29d10c03efca6a25
LinuxLinux5.19

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89751?
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use: u64 mask = GENMASK(BITS_PER_BYTE * size, 0); GENMASK(h, l) includes bit h. For size=1 (INB), this produces GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8 bits). The mask is one bit too wide for all I/O sizes. Fix the mask calculation.
How severe is CVE-2026-89751?
Severity scoring for CVE-2026-89751 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-89751?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89751?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST