SB2026092521 - Out-of-bounds read in Linux kernel amd amdgpu driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-97428)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read memory out of bounds.
The vulnerability exists due to improper bounds checking in the AMDGPU FRU EEPROM product information parser when parsing truncated or malformed FRU data. A local user can supply truncated or malformed FRU data to read memory out of bounds.
Remediation
Install update from vendor's website.