Out-of-bounds write in Linux kernel - CVE-2026-97494
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the amdgpu PSP firmware-copy routine psp_copy_fw when copying an oversized firmware image into the PSP private buffer. A local user can invoke PSP firmware-loading operations with an oversized firmware image to cause memory corruption.