Out-of-bounds read in Linux kernel - CVE-2026-98053
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to read memory out of bounds.
The vulnerability exists due to an out-of-bounds read in avs_path_module_send_init_configs() when processing module initialization configuration IDs. A local user can supply an initialization configuration ID equal to or greater than the number of initialization configurations to read memory out of bounds.