In the Linux kernel, the following vulnerability has been resolved: genirq/proc: Size interrupt directory names for 10-digit interrupt numbers /proc/irq/<n>/ directory names are built in `char name[10]` buffers with `sprintf(name, "%u", irq)`. Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and current sparse-IRQ configurations allow interrupt numbers in that range. Size the temporary name buffer for the current decimal form and switch to bounded formatting when creating or removing the proc entry.
CVE-2026-97503
NONE
EPSS 0.14%
Updated Sep 28, 2026
Linux
CVE Details
CVE ID
CVE-2026-97503
Published Date
Sep 24, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.2th percentile (higher than 3.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory