CVE-2026-80593

8.4

Linux · Kernel

A vulnerability in the Linux kernel asus_atk0110 driver allows an out-of-bounds read due to improper validation of ACPI package elements.

Executive summary

An out-of-bounds read vulnerability in the Linux kernel asus_atk0110 driver could allow a local attacker to cause a system crash or potentially gain unauthorized information access.

Vulnerability

The asus_atk0110 driver fails to check the size of ACPI sub-packages before accessing them, leading to an out-of-bounds read when processing malformed firmware data. The attack vector is local, requiring no user interaction or elevated privileges to trigger the memory access flaw.

Business impact

Successful exploitation of this vulnerability can result in a kernel panic, leading to denial of service for the affected system. While the CVSS score of 8.4 indicates high severity due to the potential for memory corruption, the local nature of the attack requires an attacker to have already gained a foothold on the target machine. This flaw poses a risk to system stability and availability for environments relying on hardware monitoring features.

Remediation

Immediate Action: Update the Linux kernel to the versions specified in the enrichment data (5.10.261, 5.15.212, 6.1.178, 6.6.145, or later) to ensure the patch is applied.

Proactive Monitoring: Monitor system logs for kernel oops or unexpected system reboots that may indicate memory access violations or driver instability.

Compensating Controls: Ensure that only authorized users have local access to systems, as this vulnerability cannot be exploited remotely.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a significant stability risk for affected Linux systems. Administrators should prioritize patching the kernel during the next scheduled maintenance window to remediate the out-of-bounds read flaw. Given that kernel-level vulnerabilities can be leveraged for further exploitation, prompt application of the upstream security updates is strongly advised.

More Linux CVEs

Sources