PT-2026-98690 · Linux · Linux Kernel
CVE-2026-98027
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the
mv88e6xxx get rxnfc() function within the net: dsa: mv88e6xxx module. The function uses rxnfc->rule cnt as a write index when dumping the policy IDR, which overwrites the input value representing the buffer size provided by the caller. Because the ETHTOOL GRXCLSRLALL operation does not require CAP NET ADMIN privileges, any user can request fewer slots than the number of existing rules, leading to a buffer overflow. Additionally, providing a rule cnt of 0 results in a NULL buffer pointer being dereferenced.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel