Parsing Flaw in Linux Kernel Affecting PHY Status Reporting
CVE-2026-97500

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97500?

A parsing flaw in the Linux kernel's handling of PHY status Information Elements (IE) has been detected, which may lead to potential security risks. Specifically, hardware can report PHY status with an unexpected length, causing the parser to potentially access memory out of bounds. This issue arises when the length is not adequately verified before parsing the PHY status IE, resulting in an elevated risk of exploitation. Proper validation measures have been introduced to ensure length checks are conducted prior to parsing to mitigate this vulnerability.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 213f9e0ab2b4f35fe8d342333238c6cc91513fbf

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 98e5720afd7495eece580238f232e3b3b4c022da

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 884495c39de1a02f42bd40051b921e2311d6ac91

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.