CVE-2026-97503 is a vulnerability in Linux Kernel
Published on September 24, 2026
genirq/proc: Size interrupt directory names for 10-digit interrupt numbers
In the Linux kernel, the following vulnerability has been resolved:
genirq/proc: Size interrupt directory names for 10-digit interrupt numbers
/proc/irq/<n>/ directory names are built in `char name[10]` buffers
with `sprintf(name, "%u", irq)`.
Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and
current sparse-IRQ configurations allow interrupt numbers in that range.
Size the temporary name buffer for the current decimal form and switch
to bounded formatting when creating or removing the proc entry.
Products Associated with CVE-2026-97503
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below d4b22fbae70037299e96539c330e4a1054b28a91 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below c2c7983c93f5d86962318be7e7298f1bc3feb1a6 is affected.
- Before 6.18.53 is affected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2, <= * is unaffected.