CVE-2026-92522
Last modified
CVE-2026-92522 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields.
Description
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 5601bd81bc290a724ed47797d22c16cba4d7ed9f; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < ff82e3374e9103d046b2a82f4315d9a422ff097d; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 2a5520065e76000f8c979d3d7b3d861ccaaecf1e; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 8e67b58c04990817ac2dbf8ae03353be6a358cd4; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 74d84320f8e37955eb286a7777843d554e6e75b2; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 4d8ecaa332c163f2b44aa5027bf061950b71b5f3; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 355bee5f11acb116cd256588631b4028ca562646; >= ecf5636dcd59cd5508641f995cc4c2bafedbb995, < 2c50ffdc73f3a70d745d249f509fc290754121e6 |
| Linux | Linux | 4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92522?
How severe is CVE-2026-92522?
How do I fix CVE-2026-92522?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92516In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92517In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92518In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92519In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92520In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92521In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92523In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92524In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92525In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92526A flaw has been found in itsourcecode Leave Management Syste…6.3
- CVE-2026-92527A vulnerability has been found in chatwoot up to 4.17.1. Thi…6.3
- CVE-2026-9253The WP Cost Estimation & Payment Forms Builder (E&P Forms) p…7.2
Are you affected by CVE-2026-92522?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
