CVE-2026-89909
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Free init resources if kvm_init() fails
kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the perf callbacks, and then calls kvm_init(). If kvm_init() fails its result is returned directly, but since module_init() does not run the module_exit() stuff on failure, so kvm_loongarch_env_exit() is never called and those resources are leaked.
So call kvm_loongarch_env_exit() when kvm_init() fails, matching the teardown-on-failure pattern used by riscv_kvm_init().
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89909",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2bd6ac68726131da32ace9717aa63ff68cf6605c",
"lessThan": "6bbbd7b719233645a5c120557a9ca1422e6b7a48",
"versionType": "git"
},
{
"status": "affected",
"version": "2bd6ac68726131da32ace9717aa63ff68cf6605c",
"lessThan": "6b78786ee7260d9818cf1d7a245b7a655ef83076",
"versionType": "git"
},
{
"status": "affected",
"version": "2bd6ac68726131da32ace9717aa63ff68cf6605c",
"lessThan": "3bf6f5e2e1007d38a5f35bd37e94ab645a0c40bc",
"versionType": "git"
},
{
"status": "affected",
"version": "2bd6ac68726131da32ace9717aa63ff68cf6605c",
"lessThan": "f7a1064cce3b100b54780c68529176232d8eb01e",
"versionType": "git"
}
],
"programFiles": [
"arch/loongarch/kvm/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/loongarch/kvm/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:16:59.917",
"references": [
{
"url": "https://git.kernel.org/stable/c/3bf6f5e2e1007d38a5f35bd37e94ab645a0c40bc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b78786ee7260d9818cf1d7a245b7a655ef83076",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6bbbd7b719233645a5c120557a9ca1422e6b7a48",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f7a1064cce3b100b54780c68529176232d8eb01e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Free init resources if kvm_init() fails\n\nkvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the\nper-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the\nperf callbacks, and then calls kvm_init(). If kvm_init() fails its\nresult is returned directly, but since module_init() does not run the\nmodule_exit() stuff on failure, so kvm_loongarch_env_exit() is never\ncalled and those resources are leaked.\n\nSo call kvm_loongarch_env_exit() when kvm_init() fails, matching the\nteardown-on-failure pattern used by riscv_kvm_init()."
}
],
"lastModified": "2026-09-16T11:16:59.917",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}