Out-of-bounds read in Linux kernel - CVE-2026-97453
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to read beyond the bounds of an ACPI package buffer.
The vulnerability exists due to improper validation of an encoded package length byte count in acpi_ps_get_next_package_length() when parsing ACPI package lengths. A local user can cause the function to process an encoded byte count exceeding the remaining available bytes to read beyond the bounds of an ACPI package buffer.