Vulnerability in Cirrus-QEMU Driver for Linux Kernel
CVE-2026-98142

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98142?

A vulnerability in the Cirrus-QEMU driver within the Linux kernel arises due to inadequate validation of the Base Address Register (BAR0) size during the PCI probe. The driver assumes a fixed video RAM size, leading to potential buffer overflows when a device with a smaller BAR0 size is connected. This oversight allows for the creation of oversized framebuffers that exceed the allocated memory, which may result in system instability or crashes when the display plane is updated.

Affected Version(s)

Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 0b5084a1f070ad1fc34e11945644ae034bbc774c

Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 26bd90c886218f36c9adeab206b0e27b4384e2f6

Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 144f51cd0ccc3ad47a6099917b7bb535611fb18f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.