{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "de462e5f10718517bacf2f84c8aa2804567ef7df"
            },
            {
              "fixed": "8d4343a411eaa182d323ab5b149496416015f27d"
            },
            {
              "fixed": "bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6"
            },
            {
              "fixed": "7812d6dab0698001e50e8c2f901e17da3eb6f429"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "32394df25d8e46935b442b429d74b37885c4f092"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.6.14"
            },
            {
              "fixed": "5.7"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.7.0"
            },
            {
              "fixed": "6.18.53"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97906.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbootconfig: Fix integer overflow in initrd size check\n\nSashiko reported that in get_boot_config_from_initrd(), a crafted initrd\nwith a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer\narithmetic:\n\n    data = ((void *)hdr) - size;\n\nto wrap around on 32-bit systems (or when pointer subtraction overflows).\nBecause data wraps around, the subsequent bounds check:\n\n    if ((unsigned long)data \u003c initrd_start)\n\nevaluates to false, bypassing the check. The kernel then calls\nxbc_calc_checksum(data, size), which attempts to read 4GB of memory,\nhitting unmapped pages and triggering a fatal kernel page fault during\nearly boot. Furthermore, on 64-bit systems with an initrd \u003e 4.29 GB, an\nunbounded 32-bit size can similarly bypass the initrd_start check.\n\nFix this by:\n1. Ensuring the initrd is at least large enough to contain the bootconfig\n   footer and verifying hdr is within the initrd bounds.\n2. Checking that size does not exceed XBC_DATA_MAX and does not exceed\n   the available space between initrd_start and hdr before performing\n   pointer subtraction.",
  "id": "CVE-2026-97906",
  "modified": "2026-09-27T03:30:57.239194725Z",
  "published": "2026-09-25T10:22:31.640Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7812d6dab0698001e50e8c2f901e17da3eb6f429"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8d4343a411eaa182d323ab5b149496416015f27d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/bff9a1579e2c9b2a59fdf3793becc9d7bf5ff1a6"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97906.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97906"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "bootconfig: Fix integer overflow in initrd size check"
}