← All Advisories

CVE-2026-97906

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97906

Key Details

CVECVE-2026-97906
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bootconfig: Fix integer overflow in initrd size check

Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd

with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer

arithmetic:

data = ((void *)hdr) - size;

to wrap around on 32-bit systems (or when pointer subtraction overflows).

Because data wraps around, the subsequent bounds check:

if ((unsigned long)data < initrd_start)

evaluates to false, bypassing the check. The kernel then calls

xbc_calc_checksum(data, size), which attempts to read 4GB of memory,

hitting unmapped pages and triggering a fatal kernel page fault during

early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an

unbounded 32-bit size can similarly bypass the initrd_start check.

Fix this by:

1. Ensuring the initrd is at least large enough to contain the bootconfig

footer and verifying hdr is within the initrd bounds.

2. Checking that size does not exceed XBC_DATA_MAX and does not exceed

the available space between initrd_start and hdr before performing

pointer subtraction. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97906
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97906