OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97428

HIGH · CVSS 7.7 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of FRU PIA parsing within the amdgpu driver, where improper handling could lead to out-of-bounds reads due to truncated or malformed FRU data. This could potentially allow attackers to exploit the kernel's memory, leading to system instability or unauthorized access. Organizations using affected Linux distributions, particularly those relying on amdgpu for graphics processing, should prioritize applying the patch to mitigate potential risks.

CVE
CVE-2026-97428
Severity
HIGH
CVSS
7.7
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: harden FRU PIA parsing with bounded helpers Replace the open-coded TLV walk with fru_pia_advance() and fru_pia_copy_field() helpers that bound every read by the actual EEPROM data length, preventing out-of-bounds reads on truncated or malformed FRU data.