Out-of-bounds read in Linux kernel - CVE-2026-97538
Published: September 28, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to disclose uninitialized bytes through sensor values exposed via sysfs.
The vulnerability exists due to an out-of-bounds read in the rog_ryujin_raw_event() function of the ASUS ROG Ryujin hwmon driver when processing a short HID report. An attacker with physical access can provide a short HID report to disclose uninitialized bytes through sensor values exposed via sysfs.