Out-of-bounds write in Linux kernel - CVE-2026-98027
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or compromise confidentiality and integrity.
The vulnerability exists due to an out-of-bounds write in the mv88e6xxx_get_rxnfc() policy rule dump handler when processing an ETHTOOL_GRXCLSRLALL request with fewer caller-provided slots than policy rules. A local user can issue a request specifying an insufficient rule count to write beyond the allocated buffer.
Exploitation requires policy rules to have been installed for the targeted port.