Out-of-bounds read in Linux kernel - CVE-2026-97994
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to read memory beyond the mapped descriptor ring.
The vulnerability exists due to an out-of-bounds read in the vhost/vdpa VHOST_SET_VRING_NUM handling when configuring a virtual ring queue size larger than the device maximum. A local user can set a queue size exceeding the advertised maximum to read memory beyond the mapped descriptor ring.