CVE-2026-97503

Summary

In the Linux kernel, the following vulnerability has been resolved:

genirq/proc: Size interrupt directory names for 10-digit interrupt numbers

/proc/irq/<n>/ directory names are built in char name[10] buffers with sprintf(name, &#34;%u&#34;, irq).

Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and current sparse-IRQ configurations allow interrupt numbers in that range.

Size the temporary name buffer for the current decimal form and switch to bounded formatting when creating or removing the proc entry.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d4b22fbae70037299e96539c330e4a1054b28a91affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c2c7983c93f5d86962318be7e7298f1bc3feb1a6affected
LinuxLinux0 < 6.18.53affected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References