Out-of-bounds write in Linux kernel - CVE-2026-98030

 

Out-of-bounds write in Linux kernel - CVE-2026-98030

Published: September 28, 2026


Vulnerability identifier: #VU152447
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98030
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in bcm_sf2_cfp_rule_get_all() in the Broadcom Starfighter 2 DSA driver when processing ETHTOOL_GRXCLSRLALL ioctl requests with a caller-supplied rule count. A local user can request fewer rule slots than installed CFP rules to compromise confidentiality, integrity, and availability.

Exploitation requires CFP rules to have already been installed.


Affected software

Linux kernel

How to mitigate CVE-2026-98030

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins