# CVE-2026-89730

## Summary

- **CVE ID:** CVE-2026-89730
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write

The trailing byte path in altera_cvp_send_block() dereferences a u32
pointer even when only 1-3 bytes remain in the input buffer. If the buffer
ends at a page or scatterlist boundary, this can read past the valid image
data and fault.

Copy the remaining bytes into a zero-initialized u32 before writing the
final word so only valid bytes are read from the input buffer.

## Affected Products

- Linux — Linux (34d1dc17ce978ae76e676d401b48fe9d004aa948)
- Linux — Linux (4.14)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/b138bc665e21d4422382ab43aebdf0a2b7bb9cb3)
- [CNA](https://git.kernel.org/stable/c/827ec385458adeeda651de2b6f3537e386b1a8d9)
- [CNA](https://git.kernel.org/stable/c/4dc1051939e499c838229af035464a5fc7671198)
- [CNA](https://git.kernel.org/stable/c/9da70a43b5fea60d758137f7f0ccfe19356cb5bb)
- [CNA](https://git.kernel.org/stable/c/447b3c893987a0106a65f04b62ec3271892e9d98)
- [CNA](https://git.kernel.org/stable/c/3b8938f5fbcf4a918785f9cb4b108782eb4ea717)
- [CNA](https://git.kernel.org/stable/c/2564ac3d3b8b47cd9692a5bf42d668ed7218b54e)
- [CNA](https://git.kernel.org/stable/c/8f3365ed2a5db2ac95ab70a6c47561db39d24537)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._