SB20260924134 - Out-of-bounds read in Linux kernel acpi acpica driver
Published: September 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-97453)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read beyond the bounds of an ACPI package buffer.
The vulnerability exists due to improper validation of an encoded package length byte count in acpi_ps_get_next_package_length() when parsing ACPI package lengths. A local user can cause the function to process an encoded byte count exceeding the remaining available bytes to read beyond the bounds of an ACPI package buffer.
Remediation
Install update from vendor's website.