Bug 2532300 (CVE-2026-89721)

Summary: CVE-2026-89721 kernel: phy: rockchip-samsung-dcphy: fix out-of-range max_register
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's `phy: rockchip-samsung-dcphy` component. A local attacker with access to the `regmap debugfs` interface could trigger an out-of-bounds read by attempting to dump registers. This occurs because the `max_register` value is incorrectly set, causing the system to read beyond the allocated memory region. Successful exploitation leads to a kernel crash (oops) and a subsequent deadlock of physical layer (PHY) operations, resulting in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-11 22:13:27 UTC
In the Linux kernel, the following vulnerability has been resolved:

phy: rockchip-samsung-dcphy: fix out-of-range max_register

The PHY register block is 64KB, so with a register stride of 4 the
last accessible register sits at offset 0xfffc. max_register names
0x10000, one register past the end of the mapping: dumping the
registers through the regmap debugfs interface reads beyond the
ioremapped region and oopses on the unmapped page. The oops fires
with the regmap lock held, so later PHY operations deadlock.