Out-of-bounds write in Linux kernel - CVE-2026-43175
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the rs9 clock driver when registering clock hardware pointers for the 9FGV0841 chip. A local user can trigger the vulnerable driver path to cause a denial of service.
Memory corruption may affect adjacent members of struct rs9_driver_data, and the kernel is reported to crash when the driver is unbound or during suspend.