Out-of-bounds write in Linux kernel - CVE-2026-97495
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds write.
The vulnerability exists due to improper bounds checking in the allocate_doorbell function when specifying a doorbell ID for restoration. A local user can provide a doorbell ID that exceeds the maximum number of queues per process to perform an out-of-bounds write.
The specific doorbell ID option is used by CRIU.