Out-of-bounds write in Linux kernel - CVE-2026-98142
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the cirrus-qemu driver's VRAM handling when updating a display plane for a PCI device with an undersized BAR0. A local user can cause a PCI device with a BAR0 smaller than the expected VRAM size to be bound to the driver to cause a denial of service.