Junglewise Threat Intelligence

CVE-2026-23288: Linux Kernel accel/amdxdna out-of-bounds write in command slot handling

CVE-2026-23288 · Severity: high · CVSS 7.8 · Published 2026-03-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD XDNA accelerator driver could allow a local user to cause memory corruption. The issue occurs when the system clears memory for a command before checking if there is enough space available. This could lead to system instability or potentially allow an attacker to gain elevated privileges.

Technical details

An out-of-bounds write vulnerability exists in the 'accel/amdxdna' driver within the Linux kernel. The root cause is a 'memset()' call in 'aie2_message.c' that clears a command header before validating that the remaining space in the command slot is sufficient. If the slot is smaller than the header, 'memset()' writes past the allocated buffer, leading to memory corruption. An attacker with local access could exploit this to trigger a kernel crash or achieve privilege escalation. The fix involves reordering the code to perform size validation before the 'memset()' operation.

Affected products

  • Linux Linux Kernel 6.19.4 to 6.19.7, 7.0-rc1

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: advisory
  • 2026-02-23: patched

References

Related threats