« Volver al listado

CVE-2026-97906

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bootconfig: Fix integer overflow in initrd size check

Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer arithmetic:

to wrap around on 32-bit systems (or when pointer subtraction overflows). Because data wraps around, the subsequent bounds check:

evaluates to false, bypassing the check. The kernel then calls xbc_calc_checksum(data, size), which attempts to read 4GB of memory, hitting unmapped pages and triggering a fatal kernel page fault during early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an unbounded 32-bit size can similarly bypass the initrd_start check.

Detalles técnicos trazas, registros y código del informe original
    data = ((void *)hdr) - size;

    if ((unsigned long)data < initrd_start)

Fix this by:
1. Ensuring the initrd is at least large enough to contain the bootconfig
   footer and verifying hdr is within the initrd bounds.
2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
   the available space between initrd_start and hdr before performing
   pointer subtraction.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97906",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
              "lessThan": "4d45bc0f8cdf606d5409b5f64a8a6609f6520c03",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
              "lessThan": "8d4343a411eaa182d323ab5b149496416015f27d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
              "lessThan": "bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
              "lessThan": "7812d6dab0698001e50e8c2f901e17da3eb6f429",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32394df25d8e46935b442b429d74b37885c4f092",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.6.14",
              "lessThan": "5.7",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "init/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "init/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:17.517",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4d45bc0f8cdf606d5409b5f64a8a6609f6520c03",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7812d6dab0698001e50e8c2f901e17da3eb6f429",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d4343a411eaa182d323ab5b149496416015f27d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbootconfig: Fix integer overflow in initrd size check\n\nSashiko reported that in get_boot_config_from_initrd(), a crafted initrd\nwith a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer\narithmetic:\n\n    data = ((void *)hdr) - size;\n\nto wrap around on 32-bit systems (or when pointer subtraction overflows).\nBecause data wraps around, the subsequent bounds check:\n\n    if ((unsigned long)data < initrd_start)\n\nevaluates to false, bypassing the check. The kernel then calls\nxbc_calc_checksum(data, size), which attempts to read 4GB of memory,\nhitting unmapped pages and triggering a fatal kernel page fault during\nearly boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an\nunbounded 32-bit size can similarly bypass the initrd_start check.\n\nFix this by:\n1. Ensuring the initrd is at least large enough to contain the bootconfig\n   footer and verifying hdr is within the initrd bounds.\n2. Checking that size does not exceed XBC_DATA_MAX and does not exceed\n   the available space between initrd_start and hdr before performing\n   pointer subtraction."
    }
  ],
  "lastModified": "2026-10-03T11:18:08.970",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}