PT-2026-98690 · Linux · Linux Kernel

CVE-2026-98027

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the mv88e6xxx get rxnfc() function within the net: dsa: mv88e6xxx module. The function uses rxnfc->rule cnt as a write index when dumping the policy IDR, which overwrites the input value representing the buffer size provided by the caller. Because the ETHTOOL GRXCLSRLALL operation does not require CAP NET ADMIN privileges, any user can request fewer slots than the number of existing rules, leading to a buffer overflow. Additionally, providing a rule cnt of 0 results in a NULL buffer pointer being dereferenced.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98027

Affected Products

Linux Kernel