PT-2026-98570 · Linux · Linux

CVE-2026-97906

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bootconfig: Fix integer overflow in initrd size check
Sashiko reported that in get boot config from initrd(), a crafted initrd with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer arithmetic:
data = ((void *)hdr) - size;
to wrap around on 32-bit systems (or when pointer subtraction overflows). Because data wraps around, the subsequent bounds check:
if ((unsigned long)data < initrd start)
evaluates to false, bypassing the check. The kernel then calls xbc calc checksum(data, size), which attempts to read 4GB of memory, hitting unmapped pages and triggering a fatal kernel page fault during early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an unbounded 32-bit size can similarly bypass the initrd start check.
Fix this by:
  1. Ensuring the initrd is at least large enough to contain the bootconfig footer and verifying hdr is within the initrd bounds.
  2. Checking that size does not exceed XBC DATA MAX and does not exceed the available space between initrd start and hdr before performing pointer subtraction.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97906

Affected Products

Linux