{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97454","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.871Z","datePublished":"2026-09-24T16:04:10.819Z","dateUpdated":"2026-10-03T10:58:38.664Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:38.664Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: add boundary checks in acpi_ps_get_next_field()\n\nAdd boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds\naccess."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The truncated bytes are a Field/BankField/IndexField FieldList inside a local DSDT/SSDT, not a network PDU. acpi_bus_init() calls acpi_load_tables() → acpi_tb_load_namespace() → acpi_ns_load_table() → acpi_ns_execute_table() → acpi_ps_parse_aml() → acpi_ps_parse_loop() → acpi_ps_get_next_arg(ARGP_FIELDLIST) → acpi_ps_get_next_field().\nAC:L - A NamedField with fewer than ACPI_NAMESEG_SIZE bytes left before aml_end makes ACPI_MOVE_32_TO_32(&name, parser_state->aml) over-read on every load; AccessField/ExtAccessField similarly ACPI_GET8 past the buffer. The table author sets those AML bytes, with no race.\nPR:N - acpi_bus_init() calls acpi_load_tables() at boot with no capable() check, so a DSDT/SSDT whose FieldList is truncated reaches acpi_ps_get_next_field() with no Linux uid or user-namespace privilege.\nUI:N - acpi_ns_execute_table() parses module-level Field/BankField/IndexField opcodes while acpi_load_tables() runs from acpi_bus_init() on ordinary power-on; no victim mount, sysfs open, or module load is required to reach acpi_ps_get_next_field().\nS:U - The over-read is of kernel heap adjacent to the ACPI table buffer parsed by host ACPICA in acpi_ps_get_next_field(); it does not cross a KVM/Xen, IOMMU, or sandbox boundary.\nC:H - Without aml_end checks, acpi_ps_get_next_field() ACPI_MOVE_32_TO_32-reads a NameSeg and ACPI_GET8-reads Access/ExtAccess bytes past the table heap object (ASAN: 4-byte read past a 175-byte allocation). ARGP_FIELDLIST keeps looping while aml < pkg_end from the attacker-chosen Field PkgLength, so the walk is not capped to a few header bytes.\nI:N - ASAN reports a READ of size 4 in AcpiPsGetNextField; ACPI_MOVE_32_TO_32 and ACPI_GET8 only fill local name/access_type variables and the newly allocated field op. The function never stores through parser_state->aml, so there is no out-of-bounds write.\nA:H - The ASAN heap-buffer-overflow is the NamedField ACPI_MOVE_32_TO_32 immediately past the 175-byte table allocation (shadow redzone). A read off that slab object during acpi_load_tables() can oops or panic the kernel at boot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/psargs.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1d704a9ba665f8d1598fc6f37a76cbd6547cdcb1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6ecf2a4855a728c4c46e33919fea9480052d62a7","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6509f56df51235fe447b624e40c098082717625c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7d97ecf2a4c7a77a9daa3fe76790ddecddc9cd0c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"add715fc1ef5b0a71afe22b3f02aa28775d9ba62","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bc5b2158c7626e3e8a78c5bb93ce0a734a26b84a","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e15aa60de0256d63df2331bf5a4bc4dd287504cd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/psargs.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1d704a9ba665f8d1598fc6f37a76cbd6547cdcb1"},{"url":"https://git.kernel.org/stable/c/6ecf2a4855a728c4c46e33919fea9480052d62a7"},{"url":"https://git.kernel.org/stable/c/6509f56df51235fe447b624e40c098082717625c"},{"url":"https://git.kernel.org/stable/c/7d97ecf2a4c7a77a9daa3fe76790ddecddc9cd0c"},{"url":"https://git.kernel.org/stable/c/add715fc1ef5b0a71afe22b3f02aa28775d9ba62"},{"url":"https://git.kernel.org/stable/c/bc5b2158c7626e3e8a78c5bb93ce0a734a26b84a"},{"url":"https://git.kernel.org/stable/c/e15aa60de0256d63df2331bf5a4bc4dd287504cd"}],"title":"ACPICA: add boundary checks in acpi_ps_get_next_field()","x_generator":{"engine":"bippy-1.2.0"}}}}