GHSA-7j5w-cr4g-jjc9unknown

In the Linux kernel, the following vulnerability has been resolved: genirq/proc: Size interrupt...

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

genirq/proc: Size interrupt directory names for 10-digit interrupt numbers

/proc/irq// directory names are built in char name[10] buffers with sprintf(name, "%u", irq).

Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and current sparse-IRQ configurations allow interrupt numbers in that range.

Size the temporary name buffer for the current decimal form and switch to bounded formatting when creating or removing the proc entry.

🔗 References (4)