Out-of-bounds read in Linux kernel - CVE-2026-97423
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to read memory out of bounds.
The vulnerability exists due to an out-of-bounds read in the cxl/region construct_region() function when constructing a region with an unresolved partition index. A local user can trigger region construction with an unresolved partition index to read memory out of bounds.
The partition index has an initial value of -1 when it has not been resolved.