-
CVE-2026-97503
- EPSS 0.15%
- Veröffentlicht 24.09.2026 16:04:50
- Zuletzt bearbeitet 28.09.2026 06:16:36
- Erkennungen
genirq/proc: Size interrupt directory names for 10-digit interrupt numbers
In the Linux kernel, the following vulnerability has been resolved: genirq/proc: Size interrupt directory names for 10-digit interrupt numbers /proc/irq/<n>/ directory names are built in `char name[10]` buffers with `sprintf(name, "%u", irq)`. Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and current sparse-IRQ configurations allow interrupt numbers in that range. Size the temporary name buffer for the current decimal form and switch to bounded formatting when creating or removing the proc entry.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
721255b9826bd11c7a38b585905fc2dd0fb94e52
Version <
d4b22fbae70037299e96539c330e4a1054b28a91
Status
affected
Version
721255b9826bd11c7a38b585905fc2dd0fb94e52
Version <
c2c7983c93f5d86962318be7e7298f1bc3feb1a6
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.5
Status
affected
Version
0
Version <
6.5
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/d4b22fbae70037299e96539c330e4a1054b28a91
https://git.kernel.org/stable/c/c2c7983c93f5d86962318be7e7298f1bc3feb1a6