Out-of-bounds read in Linux kernel - CVE-2026-98145
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in aie2_cmdlist_multi_execbuf when submitting an EXEC_CMD command chain with a zero command count. A local user can submit a command chain carrying no commands to cause a denial of service.
The fault occurs on firmware without AIE2_NPU_COMMAND support when execution reaches the command opcode handling path.