Out-of-bounds read in Linux kernel - CVE-2026-97587

 

Out-of-bounds read in Linux kernel - CVE-2026-97587

Published: September 28, 2026


Vulnerability identifier: #VU152624
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97587
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the RISC-V performance monitoring unit counter mask handling when processing available counter masks on RV32 systems. A local user can trigger performance counter handling that iterates beyond the single unsigned long counter mask to disclose sensitive information.

On RV32 systems, the counter iteration limit is 64 while an unsigned long counter mask has only 32 bits.


Affected software

Linux kernel

How to mitigate CVE-2026-97587

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins