Heap-based buffer overflow in Linux kernel - CVE-2026-89575
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a heap-based buffer overflow.
The vulnerability exists due to improper buffer size calculation in build_constructor_string() when formatting a maximum-length u64 value. A local privileged user can cause sprintf() to write a terminating NUL byte beyond the allocated buffer space to cause a heap-based buffer overflow.