Out-of-bounds read in Linux kernel - CVE-2026-97917

 

Out-of-bounds read in Linux kernel - CVE-2026-97917

Published: September 28, 2026


Vulnerability identifier: #VU152560
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97917
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to read memory outside the intended buffer.

The vulnerability exists due to an out-of-bounds read in ivpu_to_cpu_addr() when processing IPC messages containing buffer addresses. A local user can cause IPC processing to use an address range that extends beyond the buffer to read memory outside the intended buffer.


Affected software

Linux kernel

How to mitigate CVE-2026-97917

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins