Out-of-bounds write in Linux kernel - CVE-2026-98027

 

Out-of-bounds write in Linux kernel - CVE-2026-98027

Published: September 28, 2026


Vulnerability identifier: #VU152444
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98027
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service or compromise confidentiality and integrity.

The vulnerability exists due to an out-of-bounds write in the mv88e6xxx_get_rxnfc() policy rule dump handler when processing an ETHTOOL_GRXCLSRLALL request with fewer caller-provided slots than policy rules. A local user can issue a request specifying an insufficient rule count to write beyond the allocated buffer.

Exploitation requires policy rules to have been installed for the targeted port.


Affected software

Linux kernel

How to mitigate CVE-2026-98027

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins