{"id":"CVE-2026-97503","published":"2026-09-24T17:17:28.080","lastModified":"2026-09-28T06:16:36.273","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngenirq/proc: Size interrupt directory names for 10-digit interrupt numbers\n\n/proc/irq/<n>/ directory names are built in `char name[10]` buffers\nwith `sprintf(name, \"%u\", irq)`.\n\nTen-digit IRQ numbers already need 11 bytes including the trailing NUL, and\ncurrent sparse-IRQ configurations allow interrupt numbers in that range.\n\nSize the temporary name buffer for the current decimal form and switch\nto bounded formatting when creating or removing the proc entry.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/c2c7983c93f5d86962318be7e7298f1bc3feb1a6","tags":[]},{"url":"https://git.kernel.org/stable/c/d4b22fbae70037299e96539c330e4a1054b28a91","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}