Out-of-bounds read in Linux kernel - CVE-2026-92522
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to read out-of-bounds memory.
The vulnerability exists due to improper bounds validation in the ACPI IOAPIC hotplug lookup when parsing MADT and _MAT records. A local privileged user can provide a malformed record with a truncated header, an oversized declared length, or an incomplete IOAPIC body to read out-of-bounds memory.
Only builds with CONFIG_ACPI_HOTPLUG_IOAPIC enabled include the affected code.
Affected software
How to mitigate CVE-2026-92522
External References
- https://git.kernel.org/stable/c/2a5520065e76000f8c979d3d7b3d861ccaaecf1e
- https://git.kernel.org/stable/c/2c50ffdc73f3a70d745d249f509fc290754121e6
- https://git.kernel.org/stable/c/355bee5f11acb116cd256588631b4028ca562646
- https://git.kernel.org/stable/c/4d8ecaa332c163f2b44aa5027bf061950b71b5f3
- https://git.kernel.org/stable/c/5601bd81bc290a724ed47797d22c16cba4d7ed9f
- https://git.kernel.org/stable/c/74d84320f8e37955eb286a7777843d554e6e75b2
- https://git.kernel.org/stable/c/8e67b58c04990817ac2dbf8ae03353be6a358cd4
- https://git.kernel.org/stable/c/ff82e3374e9103d046b2a82f4315d9a422ff097d