Количество 5
Количество 5
CVE-2026-92522
(In the Linux kernel, the following vulnerability has been resolved: A ...)
CVE-2026-92522
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths.
CVE-2026-92522
ACPI: processor: validate MADT IOAPIC entry bounds
CVE-2026-92522
In the Linux kernel, the following vulnerability has been resolved: A ...
GHSA-jg3q-2vpp-2763
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-92522 (In the Linux kernel, the following vulnerability has been resolved: A ...) | CVSS3: 7.3 | 0% Низкий | 7 дней назад | |
CVE-2026-92522 In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths. | CVSS3: 7.3 | 0% Низкий | 7 дней назад | |
CVE-2026-92522 ACPI: processor: validate MADT IOAPIC entry bounds | CVSS3: 7.1 | 0% Низкий | около 18 часов назад | |
CVE-2026-92522 In the Linux kernel, the following vulnerability has been resolved: A ... | CVSS3: 7.3 | 0% Низкий | 7 дней назад | |
GHSA-jg3q-2vpp-2763 In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT path likewise passed a generic header to the IOAPIC helper. Validate that a current record has a complete generic header, that its declared length is contained in the available record range, and that a typed IOAPIC record contains the full fixed IOAPIC body before reading its fields. Use the same relation for both MADT and _MAT provider paths. | CVSS3: 7.3 | 0% Низкий | 7 дней назад |
Уязвимостей на страницу