CVE-2026-89906: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Refactor jump offset calculation in tail call The old macro-based jmp_offset calculation derives the jump distance from a stale prior-pass code stride, which can lead to wrong branch offsets and soft lockups under extra JIT passes. Fix this by calculating the offset directly on the absolute target: "ctx->offset[insn + 1] - ctx->idx". To avoid a false 16-bit range check abort during size estimation, add a "ctx->image == NULL" guard to inject a safe dummy offset.

Affected products

  • Linux Linux: from 6.1.149, before 6.2 (fixed in 6.2); from 6.6.103, before 6.7 (fixed in 6.7); from 6.12.43, before 6.13 (fixed in 6.13); from 6.15.11, before 6.16 (fixed in 6.16); from 6.16.2, before 6.17 (fixed in 6.17); from 6.17, before 6.18.51 (fixed in 6.18.51); …

Published 2026-09-16. Last modified 2026-09-16.