#VU124554 Out-of-bounds write in Linux kernel - CVE-2026-23305

 

#VU124554 Out-of-bounds write in Linux kernel - CVE-2026-23305

Published: March 25, 2026


Vulnerability identifier: #VU124554
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-23305
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local user to cause a denial of service, disclose sensitive information, and potentially execute arbitrary code.

The vulnerability exists due to a boundary error in the rocket driver when handling device probe error paths. A local user can trigger improper unwinding during initialization failure to cause out-of-bounds memory accesses.

Exploitation requires loading or probing of the rocket accelerator driver, which may require privileged access to trigger device initialization.


Remediation

Install security update from vendor's repository.

External links