« Volver al listado

CVE-2026-98272

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: mvpp2: prevent buffer overflow in page_pool allocation

The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools.

However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds.

Leer descripción completaMostrar menos

Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98272",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "dfd46b5584a5881b131008767950e1ab82713c8c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "e7f30dcfa6c64033bf9137362517bd248e5be384",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "f0e7d62c1eb984dd204095118973c59604144cd8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "1734c3fc0066e228ce1c11e434b7c2527f0a949a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7d04b0b13b1175ce0c4bdc77f1278c1f120f874f",
              "lessThan": "14cb1e7702e5cb3c58888f6aed498381a73927d2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:16.780",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/14cb1e7702e5cb3c58888f6aed498381a73927d2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1734c3fc0066e228ce1c11e434b7c2527f0a949a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dfd46b5584a5881b131008767950e1ab82713c8c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e7f30dcfa6c64033bf9137362517bd248e5be384",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0e7d62c1eb984dd204095118973c59604144cd8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: prevent buffer overflow in page_pool allocation\n\nThe per‑processor buffering scheme is supported only if the\nnumber of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).\nThis is already checked in mvpp2_probe() during the initial\nactivation of percpu_pools.\n\nHowever, mvpp2_change_mtu() may later call\nmvpp2_bm_switch_buffers(priv, true) without this check, which can\nlead to an out-of-bounds access in the priv->page_pool array in\nmvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ\nentries, and mvpp2_get_nrxqs() may return exactly that value. The\nper-CPU scheme then doubles it to nrxqs * 2, exceeding the array\nbounds.\n\nCheck that the hardware version is MVPP22 or newer and that the\nnumber of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS\nbefore switching to per-CPU mode.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
    }
  ],
  "lastModified": "2026-10-06T09:18:16.780",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}