Out-of-bounds read in Linux kernel - CVE-2026-98203
Published: October 8, 2026
Vulnerability details
The vulnerability allows a local user to trigger an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in soc_button_get_button_info() in drivers/input/misc/soc_button_array.c when processing an empty ACPI button descriptor package. A local user can trigger access to btns_desc->package.elements[0] with a zero package count to trigger an out-of-bounds read.
Affected software
How to mitigate CVE-2026-98203
External References
- https://git.kernel.org/stable/c/12d80e6351556cfecbdd09416e5e4c73d6ca08ba
- https://git.kernel.org/stable/c/42c7afc0e5f5b5e12e9689e9a9815b5824cf0efb
- https://git.kernel.org/stable/c/8a70a192e3e5b3ccbeeaf149c931cf45b8e82155
- https://git.kernel.org/stable/c/c3a94bfedfa2e4c4d37d1181e8db1ab010f1321a
- https://git.kernel.org/stable/c/c62c6944c680bc4ae188ca9045daada32fcd10ec
- https://git.kernel.org/stable/c/eb5563386fb8c5dbb55d902a71a0ce10e4f307eb
- https://git.kernel.org/stable/c/ec0576dabd6bf4f6532c5f0a58c9bf57095e45a4
- https://git.kernel.org/stable/c/fb5022278b6ea7f1838e3ef78028d5d5e3375f65