CVE-2026-97906
In the Linux kernel, the following vulnerability has been resolved:
bootconfig: Fix integer overflow in initrd size check
Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer arithmetic:
to wrap around on 32-bit systems (or when pointer subtraction overflows). Because data wraps around, the subsequent bounds check:
evaluates to false, bypassing the check. The kernel then calls xbc_calc_checksum(data, size), which attempts to read 4GB of memory, hitting unmapped pages and triggering a fatal kernel page fault during early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an unbounded 32-bit size can similarly bypass the initrd_start check.
Detalles técnicos trazas, registros y código del informe original
data = ((void *)hdr) - size;
if ((unsigned long)data < initrd_start)
Fix this by:
1. Ensuring the initrd is at least large enough to contain the bootconfig
footer and verifying hdr is within the initrd bounds.
2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
the available space between initrd_start and hdr before performing
pointer subtraction.CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97906",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
"lessThan": "4d45bc0f8cdf606d5409b5f64a8a6609f6520c03",
"versionType": "git"
},
{
"status": "affected",
"version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
"lessThan": "8d4343a411eaa182d323ab5b149496416015f27d",
"versionType": "git"
},
{
"status": "affected",
"version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
"lessThan": "bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6",
"versionType": "git"
},
{
"status": "affected",
"version": "de462e5f10718517bacf2f84c8aa2804567ef7df",
"lessThan": "7812d6dab0698001e50e8c2f901e17da3eb6f429",
"versionType": "git"
},
{
"status": "affected",
"version": "32394df25d8e46935b442b429d74b37885c4f092",
"versionType": "git"
},
{
"status": "affected",
"version": "5.6.14",
"lessThan": "5.7",
"versionType": "semver"
}
],
"programFiles": [
"init/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"init/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:17.517",
"references": [
{
"url": "https://git.kernel.org/stable/c/4d45bc0f8cdf606d5409b5f64a8a6609f6520c03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7812d6dab0698001e50e8c2f901e17da3eb6f429",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8d4343a411eaa182d323ab5b149496416015f27d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbootconfig: Fix integer overflow in initrd size check\n\nSashiko reported that in get_boot_config_from_initrd(), a crafted initrd\nwith a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer\narithmetic:\n\n data = ((void *)hdr) - size;\n\nto wrap around on 32-bit systems (or when pointer subtraction overflows).\nBecause data wraps around, the subsequent bounds check:\n\n if ((unsigned long)data < initrd_start)\n\nevaluates to false, bypassing the check. The kernel then calls\nxbc_calc_checksum(data, size), which attempts to read 4GB of memory,\nhitting unmapped pages and triggering a fatal kernel page fault during\nearly boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an\nunbounded 32-bit size can similarly bypass the initrd_start check.\n\nFix this by:\n1. Ensuring the initrd is at least large enough to contain the bootconfig\n footer and verifying hdr is within the initrd bounds.\n2. Checking that size does not exceed XBC_DATA_MAX and does not exceed\n the available space between initrd_start and hdr before performing\n pointer subtraction."
}
],
"lastModified": "2026-10-03T11:18:08.970",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}