Numeric Truncation Error in Linux kernel - CVE-2026-98157
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to numeric truncation and insufficient input validation in the poll_msec sysfs store handler when processing user-supplied polling-delay values. A local user can write a zero value or an oversized value that truncates to zero to cause a denial of service.