CVE-2026-89751 is a vulnerability in Linux Kernel
Published on September 11, 2026
x86/tdx: Fix off-by-one in port I/O handling
In the Linux kernel, the following vulnerability has been resolved:
x86/tdx: Fix off-by-one in port I/O handling
handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use:
u64 mask = GENMASK(BITS_PER_BYTE * size, 0);
GENMASK(h, l) includes bit h. For size=1 (INB), this produces
GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8
bits). The mask is one bit too wide for all I/O sizes.
Fix the mask calculation.
Products Associated with CVE-2026-89751
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 03149948832a078f759022ed5b92e722d8d23c26 and below 222b7005e4519f633b4cd666226256abbab46a1a is affected.
- Version 03149948832a078f759022ed5b92e722d8d23c26 and below c4a22154870813d10aa0b4c734a574c726f9d4b0 is affected.
- Version 03149948832a078f759022ed5b92e722d8d23c26 and below bb45f705c4440dd3c689328319b88dd28770bbb8 is affected.
- Version 03149948832a078f759022ed5b92e722d8d23c26 and below 0f63e656b1c679d32ac595de29d10c03efca6a25 is affected.
- Version 5.19 is affected.
- Before 5.19 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.