CVE-2026-97441
Last modified
CVE-2026-97441 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ata: ahci: fail probe if BAR too small for claimed ports When an AHCI controller is disabled in BIOS, its HOST_CAP register may contain a bogus value, e.g. 0xFFFFFFFF. Since CAP.NP (Number of Ports) is a zeroes based 5-bit register field, a value of 0x1f means 32 ports.
Description
In the Linux kernel, the following vulnerability has been resolved: ata: ahci: fail probe if BAR too small for claimed ports When an AHCI controller is disabled in BIOS, its HOST_CAP register may contain a bogus value, e.g. 0xFFFFFFFF. Since CAP.NP (Number of Ports) is a zeroes based 5-bit register field, a value of 0x1f means 32 ports. If CAP.NP claims more ports than can physically fit within the mapped BAR region, accessing port registers beyond the BAR boundary causes a kernel panic. Add validation in ahci_init_one() to check that the BAR size is sufficient for the number of ports claimed in CAP.NP. The check calculates the required MMIO size as: required_size = 0x100 (global registers) + max_ports * 0x80 If required_size exceeds the actual BAR size, the probe fails with -ENODEV, preventing the panic and providing a clear error message. [cassel: commit log]
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < df262c828b616450eb351349e91c63447551bd01; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < f2e291043c37a896d7f9797e25a356dceb030177; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < c4086c6e1af757e1ff26fa2d2926b3ec0195de79 |
| Linux | Linux | 2.6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-97441?
How severe is CVE-2026-97441?
How do I fix CVE-2026-97441?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97436In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97437In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-97438In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-97439In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9744IBM Netezza Software 11.3.0.3 through Interim Fix 002 does n…5.9
- CVE-2026-97440In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97442In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-97443In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97444In the Linux kernel, the following vulnerability has been re…7.7
- CVE-2026-97445In the Linux kernel, the following vulnerability has been re…7.7
- CVE-2026-97446In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97447In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-97441?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
