Out-of-bounds read in Linux kernel - CVE-2026-97995
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause an out-of-bounds read.
The vulnerability exists due to type confusion in the virtio_console remove_vqs() function when unbinding a device with a control message remaining on the control-out virtqueue. A local privileged user can unbind the device while the control message is queued to cause an out-of-bounds read.