{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97444","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.870Z","datePublished":"2026-09-24T16:03:59.121Z","dateUpdated":"2026-10-03T10:58:28.686Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:28.686Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: add boundary checks in two places\n\nAdd boundary checks in acpi_ps_get_next_namestring() and\nacpi_ps_peek_opcode() to prevent out-of-bounds access."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The truncated AML that acpi_ps_get_next_namestring() and acpi_ps_peek_opcode() over-read is the platform DSDT/SSDT stream parsed by acpi_ns_execute_table() from acpi_load_tables() in acpi_bus_init(); those bytes come from local firmware tables, not from a network protocol message.\nAC:L - A DSDT/SSDT whose namestring (AML_MULTI_NAME_PREFIX count or a run of '\\'/'^' prefixes) or final opcode sits against the AML buffer end makes acpi_ps_get_next_namestring() and acpi_ps_peek_opcode() read past parser_state->aml_end on every acpi_load_tables() parse; the table author sets those bytes and no race is required.\nPR:N - acpi_bus_init() calls acpi_load_tables() → acpi_tb_load_namespace() → acpi_ns_load_table() → acpi_ns_execute_table() at boot with no capability check, so the OOB in acpi_ps_get_next_namestring()/acpi_ps_peek_opcode() fires on firmware AML before any user account exists.\nUI:N - acpi_load_tables() parses the DSDT/SSDT automatically during acpi_bus_init() at boot; the victim does not need to mount media, open a file, or otherwise interact.\nS:U - acpi_ns_lookup()'s ACPI_MOVE_32_TO_32 of an over-long nameseg and acpi_ps_peek_opcode()'s ACPI_GET8 over-read kernel memory adjacent to the mapped AML buffer inside the host kernel; this is not a VM escape or IOMMU bypass.\nC:H - acpi_ps_get_next_namestring() does not cap '\\'/'^' prefix walking or the AML_MULTI_NAME_PREFIX count byte, then acpi_ns_lookup() copies up to 255 four-byte namesegs via ACPI_MOVE_32_TO_32 past aml_end, so the out-of-bounds read is not limited to a few bytes.\nI:N - The demonstrated faults are heap-buffer-overflow reads (4 bytes in acpi_ns_lookup, 1–2 bytes in acpi_ps_peek_opcode); the patched functions only advance parser_state->aml and return a namestring pointer or opcode, and do not write past the AML buffer.\nA:H - The same over-read past the AML allocation in acpi_ns_lookup()/acpi_ps_peek_opcode() during acpi_load_tables() can touch unmapped memory and oops or panic the kernel at boot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/psargs.c","drivers/acpi/acpica/psparse.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3a8c1efc0fd3abb2d2b1254315f36db03abc88eb","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c917df56b73719a2d4cee1c4ab4a6626acb95315","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4f03d84c95a51436878cd750a14f8ca37eeb3112","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"38ee32a9ace6fae8965f059b38e6e7fb27b1e7ce","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"253d7272d01db9529c79b95205c0f859ef9f4f23","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4de2cffef5e6b5b79eec8c934df582459b818228","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bdc35754012906dbf094be104b103ca3adfef6f7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/psargs.c","drivers/acpi/acpica/psparse.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3a8c1efc0fd3abb2d2b1254315f36db03abc88eb"},{"url":"https://git.kernel.org/stable/c/c917df56b73719a2d4cee1c4ab4a6626acb95315"},{"url":"https://git.kernel.org/stable/c/4f03d84c95a51436878cd750a14f8ca37eeb3112"},{"url":"https://git.kernel.org/stable/c/38ee32a9ace6fae8965f059b38e6e7fb27b1e7ce"},{"url":"https://git.kernel.org/stable/c/253d7272d01db9529c79b95205c0f859ef9f4f23"},{"url":"https://git.kernel.org/stable/c/4de2cffef5e6b5b79eec8c934df582459b818228"},{"url":"https://git.kernel.org/stable/c/bdc35754012906dbf094be104b103ca3adfef6f7"}],"title":"ACPICA: add boundary checks in two places","x_generator":{"engine":"bippy-1.2.0"}}}}