SB20260928170 - Out-of-bounds write in Linux kernel net dsa driver



SB20260928170 - Out-of-bounds write in Linux kernel net dsa driver

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928170
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-98030)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in bcm_sf2_cfp_rule_get_all() in the Broadcom Starfighter 2 DSA driver when processing ETHTOOL_GRXCLSRLALL ioctl requests with a caller-supplied rule count. A local user can request fewer rule slots than installed CFP rules to compromise confidentiality, integrity, and availability.

Exploitation requires CFP rules to have already been installed.


Remediation

Install update from vendor's website.