Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97906

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bootconfig: Fix integer overflow in initrd size check<br /> <br /> Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd<br /> with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer<br /> arithmetic:<br /> <br /> data = ((void *)hdr) - size;<br /> <br /> to wrap around on 32-bit systems (or when pointer subtraction overflows).<br /> Because data wraps around, the subsequent bounds check:<br /> <br /> if ((unsigned long)data 4.29 GB, an<br /> unbounded 32-bit size can similarly bypass the initrd_start check.<br /> <br /> Fix this by:<br /> 1. Ensuring the initrd is at least large enough to contain the bootconfig<br /> footer and verifying hdr is within the initrd bounds.<br /> 2. Checking that size does not exceed XBC_DATA_MAX and does not exceed<br /> the available space between initrd_start and hdr before performing<br /> pointer subtraction.

Impacto