CVE-2026-89947

Boot-time out-of-bounds read via stale parent count

Published Sep 16, 2026 · Updated Sep 16, 2026

An out-of-bounds read in the Meson GXBB clock driver in Linux allows affected systems to read past a parent array during boot. The gxbb_32k_clk_sel mux retains a hard-coded parent count of four after its parent array was reduced to three entries, so __clk_register reads beyond gxbb_32k_clk_parents. The condition is reached during clock-controller initialization on affected Amlogic GXBB hardware; the published report demonstrates a KASAN finding on a WeTek Hub but does not establish an attacker-controlled path or a service interruption.

CVSS severityUnavailable
Unscored
EPSS probabilityUnavailable
No score available in this record
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

An out-of-bounds read in the Meson GXBB clock driver in Linux allows affected systems to read past a parent array during boot. The gxbb_32k_clk_sel mux retains a hard-coded parent count of four after its parent array was reduced to three entries, so __clk_register reads beyond gxbb_32k_clk_parents. The condition is reached during clock-controller initialization on affected Amlogic GXBB hardware; the published report demonstrates a KASAN finding on a WeTek Hub but does not establish an attacker-controlled path or a service interruption.

The record

CVE
CVE-2026-89947
Published
Sep 16, 2026
Updated
Sep 16, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
Unavailable
Attack vector
Unavailable
Privileges
Unavailable

Timeline

How it unfolded

  1. Sep 16, 2026CVE publishedPublication date reported by the CVE source.
  2. Sep 16, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=1eb7a2f3e25075b2dc9b10c94616b066f80e79ee
  2. Affected versionversion=450a1d9eac98886c7d19586dd10e72a4eaf8e1bc
  3. Affected versionversion=4d32504f7ae951600e216aac4e04c81b02421a9d <f6ff0e6995dbff5cb145d7795c8f0af9c168094a
  4. Affected versionversion=5.10.236 <5.10.270
  5. Affected versionversion=5.15.180 <5.15.221
  6. Affected versionversion=5.4.292 <5.5
  7. Affected versionversion=6.1.134 <6.1.188
  8. Affected versionversion=6.12.23 <6.12.110
  9. Affected versionversion=6.13.11 <6.14
  10. Affected versionversion=6.14.2 <6.15
  11. Affected versionversion=6.15
  12. Affected versionversion=6.6.87 <6.6.157
  13. Affected versionversion=6ded8c22af4700bbf91da24ac025f9d05b879267 <1e509a6707d2fd9da79bdfa24742661b34562bfd
  14. Affected versionversion=7061afacc89dec3f02f7412653b83f148a0c646b <404079d124d75a5da16322acc53d3ffc50b4ec68
  15. Affected versionversion=7915d7d5407c026fa9343befb4d3343f7a345f97 <4582949b7badcb91bb537ca522d69b8a35131e72
  16. Affected versionversion=7915d7d5407c026fa9343befb4d3343f7a345f97 <628b6fee9fca292f12d07f0f1bcf1edefa949d81
  17. Affected versionversion=7915d7d5407c026fa9343befb4d3343f7a345f97 <bf85bd6e550c17ffa585606fcc18eb5b7c95bbce
  18. Affected versionversion=b9778cd803b330b8d7a9b523743c35093454b77f <c86214e6178c38a0eff39110a4e92b824f5dd403
  19. Affected versionversion=f18b09c998002ed6a67d1a235f3941a2662f1036
  20. Affected versionversion=f95e0f36e592e17a24ba4f56c355946448f84291 <8b2f7a411e7ceaef268355c2150c22ee3f509c3b

What conditions does exploitation require?

Attack vectorUnavailable in this record.
Required privilegesUnavailable in this record.

What is affected?

The Linux Kernel Organization · Linuxversion=1eb7a2f3e25075b2dc9b10c94616b066f80e79ee; version=450a1d9eac98886c7d19586dd10e72a4eaf8e1bc; version=4d32504f7ae951600e216aac4e04c81b02421a9d <f6ff0e6995dbff5cb145d7795c8f0af9c168094a; version=5.10.236 <5.10.270; version=5.15.180 <5.15.221; version=5.4.292 <5.5; version=6.1.134 <6.1.188; version=6.12.23 <6.12.110; version=6.13.11 <6.14; version=6.14.2 <6.15; version=6.15; version=6.6.87 <6.6.157; version=6ded8c22af4700bbf91da24ac025f9d05b879267 <1e509a6707d2fd9da79bdfa24742661b34562bfd; version=7061afacc89dec3f02f7412653b83f148a0c646b <404079d124d75a5da16322acc53d3ffc50b4ec68; version=7915d7d5407c026fa9343befb4d3343f7a345f97 <4582949b7badcb91bb537ca522d69b8a35131e72; version=7915d7d5407c026fa9343befb4d3343f7a345f97 <628b6fee9fca292f12d07f0f1bcf1edefa949d81; version=7915d7d5407c026fa9343befb4d3343f7a345f97 <bf85bd6e550c17ffa585606fcc18eb5b7c95bbce; version=b9778cd803b330b8d7a9b523743c35093454b77f <c86214e6178c38a0eff39110a4e92b824f5dd403; version=f18b09c998002ed6a67d1a235f3941a2662f1036; version=f95e0f36e592e17a24ba4f56c355946448f84291 <8b2f7a411e7ceaef268355c2150c22ee3f509c3b

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
VectorUnavailable
PrivilegesUnavailable
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

No sourced classifications are available.

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo