CVE-2026-89594
CVE CVE-2026-89594EUVD EUVD-2026-76506Published 2026-09-11T19:44:57.000ZLast changed 2026-09-14T12:01:17.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device The OMAP SSI driver uses a synthetic HSI controller device allocated via hsi_alloc_controller(), which does not go through the normal OF/platform device initialization path. As a result, the embedded struct device does not have a DMA mask initialized by default. After recent DMA API hardening changes, dma_map_sg() and related helpers now require a valid dma_mask to be present, otherwise the driver may crash or trigger warnings when attempting DMA mapping operations. Fix this by explicitly initializing the DMA mask for the SSI controller device and setting a 32-bit DMA mask, which matches the hardware capabilities.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux f959dcd6ddfd29235030e8026471ac1b022ad2b0 <6a5426f56de98faf7886702f8720828bf346a48f; patch: 7.2.4; 4e57482e8440fac7137832629109730ea4b267aa; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <9963a65be2befff82b5f5a7cfcd7ac4aca081c0b; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <9ecef057b7a7f165ce66eaf07cb4cf85d10ed9c7; patch: 0; patch: 5.15.221; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <a4beb841f84e0e6ad5ff3d114f43ad30165572dd; patch: 6.1.188; 5.10; patch: 6.12.109; patch: 6.6.157; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <fbffbfdae55954213fea99c5c9856c48dc705019; 5.9.2 <5.10; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <e8d47e309c704df95816e7442f05947424d8b33f; patch: 7.3-rc1; patch: 5.10.270; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <e81250ec6b69248b00d38c523dc6a13efaf38aab; patch: 6.18.50; f959dcd6ddfd29235030e8026471ac1b022ad2b0 <4e019e5e247bfe877fdf288f2d6ec1b4c850c7c6
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.