Out-of-bounds read in Linux kernel - CVE-2026-97529
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the qla2xxx FC BSG vendor command handling when processing a short FC_BSG_HST_VENDOR request. A local privileged user can submit a short request with a matching vendor ID to trigger an out-of-bounds heap read.
Exploitation requires the CAP_SYS_RAWIO capability.