Out-of-bounds write in Linux kernel - CVE-2026-97493
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds write.
The vulnerability exists due to improper validation of VBIOS-reported GPIO I2C table sizes in the AMDGPU ATOMBIOS GPIO I2C table handling code when processing a VBIOS GPIO I2C table with a corrupt size field. A local user can provide a VBIOS GPIO I2C table with a corrupt size field to cause an out-of-bounds write.