Out-of-bounds read in Linux kernel - CVE-2026-97420
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to read out-of-bounds memory.
The vulnerability exists due to a missing NUL terminator in the bpf_sysctl_set_new_value helper when replacing a pending sysctl value through a cgroup/sysctl BPF program. A local privileged user can provide a replacement sysctl value without a terminating NUL byte to read out-of-bounds memory.