Vulnerability in Cirrus-QEMU Driver for Linux Kernel
CVE-2026-98142
Currently unrated
What is CVE-2026-98142?
A vulnerability in the Cirrus-QEMU driver within the Linux kernel arises due to inadequate validation of the Base Address Register (BAR0) size during the PCI probe. The driver assumes a fixed video RAM size, leading to potential buffer overflows when a device with a smaller BAR0 size is connected. This oversight allows for the creation of oversized framebuffers that exceed the allocated memory, which may result in system instability or crashes when the display plane is updated.
Affected Version(s)
Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 0b5084a1f070ad1fc34e11945644ae034bbc774c
Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 26bd90c886218f36c9adeab206b0e27b4384e2f6
Linux ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 144f51cd0ccc3ad47a6099917b7bb535611fb18f