{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97445","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.870Z","datePublished":"2026-09-24T16:04:00.409Z","dateUpdated":"2026-10-03T10:58:29.784Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:29.784Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()\n\nEnhance buffer validation in acpi_ut_walk_aml_resources() to prevent\nbuffer overflows."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Malformed AML resource bytes arrive in a Buffer from DSDT/SSDT, not a network message. acpi_ut_walk_aml_resources() is reached from acpi_ex_concat_template() during acpi_bus_init→acpi_load_tables→acpi_ns_load_table (ConcatenateResTemplate) and from acpi_rs_create_resource_list() via acpi_dev_get_resources() on _CRS; both are local firmware paths.\nAC:L - A Buffer whose remaining length is below sizeof(aml_resource_end_tag), a large descriptor shorter than the serial_bus.type field, or a 16-bit Resource Length larger than end_aml-aml makes acpi_ut_validate_resource() and acpi_rs_convert_aml_to_resources() over-read on every walk; the table author sets those bytes and no race is required.\nPR:N - acpi_bus_init() calls acpi_load_tables() which executes module-level ConcatenateResTemplate, and acpi_dev_get_resources() walks _CRS during scan, neither with a uid or capability check; a compromised DSDT/SSDT is enough with no local account.\nUI:N - acpi_ns_execute_table() evaluates module-level AML during acpi_load_tables(), and acpi_scan_claim_resources()/acpi_dev_get_resources() walk _CRS while claiming device resources; both run on ordinary power-on with no mount, file-open, or other victim action.\nS:U - The over-read is of kernel heap adjacent to the ACPI Buffer object's payload (acpi_ut_create_buffer_object) inside the host ACPICA interpreter; it does not cross a KVM/Xen, IOMMU, or sandbox boundary.\nC:H - Without the length>(end_aml-aml) check, a large vendor/GPIO/serial descriptor whose 16-bit Resource Length exceeds the remaining Buffer lets acpi_rs_convert_aml_to_resource() ACPI_RSC_MOVE*/COUNT16 copy up to that claimed length from past the heap allocation, an unbounded kernel overread rather than a few header bytes.\nI:N - AddressSanitizer and the patch comments describe a READ past the AML Buffer; acpi_ut_walk_aml_resources() only validates and optionally converts into a separately sized resource list, and ConcatenateResTemplate (user_function NULL) never stores through the over-read pointer, so there is no out-of-bounds write primitive.\nA:H - acpi_ut_validate_resource() reading common_serial_bus.type or acpi_rs_move_data() copying a claimed Resource Length past the Buffer object walks off the slab allocation and can oops/panic, matching the reported KASAN heap-buffer-overflow in AcpiUtValidateResource on the ConcatenateResTemplate path."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/utresrc.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"816badec122fe01d05265f2d306212739f5d3fdb","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cd60a407a3a6d75347a04f9271b7b561d06d21c8","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"37c794f87a72471f7ef71633ac0550ad14ac0885","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"50a11e2f3dc8a7189e7ebbd3eeafa51f16128a56","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f65e2ef7ccca11dc874f48aff996a6a26528f8e7","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d0fb1973f705c8b8bd7e118e4a9a65d05d800fba","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b2e21fe8c3361c3d0d57ee56d359bea9b51fda3d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/utresrc.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/816badec122fe01d05265f2d306212739f5d3fdb"},{"url":"https://git.kernel.org/stable/c/cd60a407a3a6d75347a04f9271b7b561d06d21c8"},{"url":"https://git.kernel.org/stable/c/37c794f87a72471f7ef71633ac0550ad14ac0885"},{"url":"https://git.kernel.org/stable/c/50a11e2f3dc8a7189e7ebbd3eeafa51f16128a56"},{"url":"https://git.kernel.org/stable/c/f65e2ef7ccca11dc874f48aff996a6a26528f8e7"},{"url":"https://git.kernel.org/stable/c/d0fb1973f705c8b8bd7e118e4a9a65d05d800fba"},{"url":"https://git.kernel.org/stable/c/b2e21fe8c3361c3d0d57ee56d359bea9b51fda3d"}],"title":"ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()","x_generator":{"engine":"bippy-1.2.0"}}}}