CVE-2026-97906
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
bootconfig: Fix integer overflow in initrd size check<br />
<br />
Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd<br />
with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer<br />
arithmetic:<br />
<br />
data = ((void *)hdr) - size;<br />
<br />
to wrap around on 32-bit systems (or when pointer subtraction overflows).<br />
Because data wraps around, the subsequent bounds check:<br />
<br />
if ((unsigned long)data 4.29 GB, an<br />
unbounded 32-bit size can similarly bypass the initrd_start check.<br />
<br />
Fix this by:<br />
1. Ensuring the initrd is at least large enough to contain the bootconfig<br />
footer and verifying hdr is within the initrd bounds.<br />
2. Checking that size does not exceed XBC_DATA_MAX and does not exceed<br />
the available space between initrd_start and hdr before performing<br />
pointer subtraction.


