Out-of-bounds read in Linux kernel - CVE-2026-97917
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to read memory outside the intended buffer.
The vulnerability exists due to an out-of-bounds read in ivpu_to_cpu_addr() when processing IPC messages containing buffer addresses. A local user can cause IPC processing to use an address range that extends beyond the buffer to read memory outside the intended buffer.