Out-of-bounds read in Linux kernel - CVE-2026-98088
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to improper handling of an invalid NUMA node value in _base_assign_reply_queues() when assigning high IOPS reply queues for a PCI device without NUMA-node affinity. A local user can trigger reply queue assignment to cause an out-of-bounds read.
The issue occurs when dev_to_node() returns NUMA_NO_NODE (-1).