Out-of-bounds write in Linux kernel - CVE-2026-98029
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption or a denial of service.
The vulnerability exists due to missing bounds checking in nfp_net_get_fs_loc() when handling ETHTOOL_GRXCLSRLALL requests with a user-supplied rule count smaller than the number of flow steering rules. A local user can issue a crafted ioctl request to write rule locations beyond the caller-provided buffer.
Exploitation requires flow steering rules to have been installed; a rule count of zero leaves the rule-locations pointer NULL.