Improper input validation in Linux kernel - CVE-2026-97441
Published: September 24, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper validation of the mapped BAR size in the AHCI driver when probing an AHCI controller whose HOST_CAP register claims more ports than fit within the mapped BAR region. An attacker with physical access can trigger access to port registers beyond the BAR boundary to cause a denial of service.