Out-of-bounds read in Linux kernel - CVE-2026-97614
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a slab out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in the Broadcom legacy FCS DSA tagger when processing a nonlinear socket buffer. A local user can send a nonlinear socket buffer through a DSA user port to cause a slab out-of-bounds read.
The issue occurs when scatter-gather and fragment-list features allow nonlinear socket buffers to reach the tagger.