{"id":"CVE-2026-90191","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-90191","summary":"mailbox: riscv-sbi-mpxy: validate RPMI notification lengths","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: riscv-sbi-mpxy: validate RPMI notification lengths\n\nThe SBI return value controls how many bytes are copied from shared\nmemory into the RPMI notification buffer. It is not validated against\nthe negotiated shared-memory size before that copy. The event walker\nalso uses a reversed loop condition and can inspect a short event record.\n\nValidate the complete notification length before copying it, iterate only\nwhile a full event header remains, and stop when a declared event payload\nextends beyond the copied notification data.","published":"2026-09-17T16:07:12.339Z","modified":"2026-09-19T03:47:25.059715529Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.18.52"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/11d5af151bcbe78f5a579e0faecd3be9cea0399a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90191.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90191"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-19T03:47:25.059715529Z"}}