« Volver al listado

CVE-2026-98155

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

accel/qaic: Address potential out-of-bounds read in resp_worker()

Although 'commit 2feec5ae5df7 ("accel/qaic: Handle DBC deactivation if the owner went away")' fixes the scenario it was intended for by walking the message and only decoding QAIC_TRANS_DEACTIVATE_FROM_DEV, if present, it skipped over the bounds checking code that is included in decode_message(). This could lead to issues such as reading past the slab allocation's end, infinite loops or kernel panics. For those issues to happen, a malformed wire message is needed to be sent from the device.

Leer descripción completaMostrar menos

Instead of duplicating the bounds checking code already present in decode_message(), use the function inside resp_worker().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98155",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "08021f2d4a557d6491e3bcc288e96425f50aa3cf",
              "lessThan": "f4b64488f3deca63f7fbc7d7c3835b2e668003f9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f403094d9075d7c565a3d81002b781c325cb3c07",
              "lessThan": "12deeade460d47031267256ba07add51cc7eabd0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2feec5ae5df785658924ab6bd91280dc3926507c",
              "lessThan": "c72e81ee46bdd4c221114d6e9515e9b4647616d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2feec5ae5df785658924ab6bd91280dc3926507c",
              "lessThan": "ab243f74ab4084ca5c8dec608cb5b0deb27db067",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2dd67966f39a2abf8ccb4865031c722e40e01b7f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee0180e77e6c8482644569632065411de844c515",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.81",
              "lessThan": "6.12.111",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.22",
              "lessThan": "6.18.53",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.134",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.12",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/accel/qaic/qaic_control.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/accel/qaic/qaic_control.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:47.157",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/12deeade460d47031267256ba07add51cc7eabd0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab243f74ab4084ca5c8dec608cb5b0deb27db067",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c72e81ee46bdd4c221114d6e9515e9b4647616d7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f4b64488f3deca63f7fbc7d7c3835b2e668003f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Address potential out-of-bounds read in resp_worker()\n\nAlthough 'commit 2feec5ae5df7 (\"accel/qaic: Handle DBC deactivation if the\nowner went away\")' fixes the scenario it was intended for by walking the\nmessage and only decoding QAIC_TRANS_DEACTIVATE_FROM_DEV, if present, it\nskipped over the bounds checking code that is included in decode_message().\nThis could lead to issues such as reading past the slab allocation's end,\ninfinite loops or kernel panics. For those issues to happen, a malformed\nwire message is needed to be sent from the device.\n\nInstead of duplicating the bounds checking code already present in\ndecode_message(), use the function inside resp_worker()."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}