« Volver al listado

CVE-2026-98146

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain

struct amdxdna_cmd_chain contains a flexible array annotated with __counted_by(command_count). Since the structure is stored in shared AMDXDNA_BO_SHARE memory, userspace can modify command_count concurrently. If command_count is changed to zero, the bounds check generated from __counted_by may fail and trigger a kernel panic.

Remove __counted_by to avoid relying on the userspace-controlled command_count for the flexible array bounds check.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98146",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "aac243092b707bb3018e951d470cc1a9bcbaba6c",
              "lessThan": "93fa3e925b15b0ded0a549fe7f12bfbb1c4e171a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aac243092b707bb3018e951d470cc1a9bcbaba6c",
              "lessThan": "52f3e086760a9a3e02a46a10b57caffd73b1c204",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aac243092b707bb3018e951d470cc1a9bcbaba6c",
              "lessThan": "b3709d354545e70388177500761f92d906c4dfd6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/accel/amdxdna/amdxdna_ctx.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/accel/amdxdna/amdxdna_ctx.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:46.147",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/52f3e086760a9a3e02a46a10b57caffd73b1c204",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/93fa3e925b15b0ded0a549fe7f12bfbb1c4e171a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b3709d354545e70388177500761f92d906c4dfd6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain\n\nstruct amdxdna_cmd_chain contains a flexible array annotated with\n__counted_by(command_count). Since the structure is stored in shared\nAMDXDNA_BO_SHARE memory, userspace can modify command_count concurrently.\nIf command_count is changed to zero, the bounds check generated from\n__counted_by may fail and trigger a kernel panic.\n\nRemove __counted_by to avoid relying on the userspace-controlled\ncommand_count for the flexible array bounds check."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}