Out-of-bounds write in Linux kernel - CVE-2026-97910

 

Out-of-bounds write in Linux kernel - CVE-2026-97910

Published: September 28, 2026


Vulnerability identifier: #VU152578
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97910
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of buffer sizes in sprd_platform_compr_copy() in the ASoC sprd PCM compression driver when handling user-configured compression buffer parameters and write data. A local user can configure oversized compression buffer parameters and write data to overflow fixed IRAM or DDR buffer allocations.

The copy callback can be reached while the stream is in the setup state without starting it.


Affected software

Linux kernel

How to mitigate CVE-2026-97910

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins