CVE-2026-89570
CVE CVE-2026-89570EUVD EUVD-2026-76481Published 2026-09-11T19:44:39.000ZLast changed 2026-09-13T06:31:07.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: cxl/mce: Make the MCE notifier per-region Flavien Solt reported lifetime issues with the CXL MCE notifier, which can lead to NULL dereferences and use-after-free in the MCE handler. The notifier was registered per memory device and stored in 'struct cxl_memdev_state', even though it only needs the region state (the region's SPA range and its extended linear cache size). Instead of keeping the memory device and endpoint alive, the correct fix is to move the notifier into 'struct cxl_region' and register it from cxl_region_probe() as it should be a per-region notifier. Setup the registration to only happen for regions that have an extended linear cache as that is the only current usage. Remove cxl_port_get_spa_cache_alias() as it is now dead code. [ dj: Update dev_warn() when notifier fails due to kconfig. (Ben) ]
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 516e5bd0b6bf4ae1ad072df637b428a737c3c870 <775d0f4558f4cec0ee0c8966595d1add1791f36e; 516e5bd0b6bf4ae1ad072df637b428a737c3c870 <491d8c9ac98d55073bda778f88a5248d4cce3fa0; patch: 7.2.4; patch: 6.18.51; patch: 0; patch: 7.3-rc1; 6.15; 516e5bd0b6bf4ae1ad072df637b428a737c3c870 <5563db13c9528a56c7161260ec75ec8690dc5608
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.