# CVE-2026-89438

## Summary

- **CVE ID:** CVE-2026-89438
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: ISST: Validate logical CPU id and clos id

Validate max CLOS ID and logical CPU ID for core power feature.
Reject any clos level or logical CPU number greater than the
supported maximum. These are used to calculate MMIO offset.

## Affected Products

- Linux — Linux (12a7d2cb811dd8a884dea088a2701fcb8d00136e)
- Linux — Linux (6.4)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/c9ee2770eb95ba316a56d776b2b66666b70c194b)
- [CNA](https://git.kernel.org/stable/c/5b032e1dda486ca41d10536bd195bd8a559af1e2)
- [CNA](https://git.kernel.org/stable/c/82d4afadb02fb4d7d7bb9230900904c10e49ec87)
- [CNA](https://git.kernel.org/stable/c/124e2dbabe460c2a6e7440f4ad8af560131295c9)
- [CNA](https://git.kernel.org/stable/c/0d601126c7afda9bb94dfecc8b2c0a16f20d76cb)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._