CVE-2026-97917

Source
https://cve.org/CVERecord?id=CVE-2026-97917
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97917.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97917
Downstream
Published
2026-09-25T10:22:38Z
Modified
2026-09-26T03:48:30Z
Summary
accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr
Details

In the Linux kernel, the following vulnerability has been resolved:

accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr

Add a size parameter to ivpu_to_cpu_addr() and validate that the whole [vpu_addr, vpu_addr + size) range stays within the BO.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97917.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
647371a6609ddf8700fe151af72e32daebb9baa7
Fixed
5419be345f32222750e006b85b7f9bae1a285c8e
Fixed
43c68f52aecd519eb682fa09d57ae52c896f860f
Fixed
29f82a2280e170429370e7a842cde4e70ead8547
Fixed
3837c3f29fbc3b8c12bebf5c62741e2befe3482a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97917.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97917.json"