PT-2026-98804 · Linux · Linux Kernel

CVE-2026-98142

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The cirrus-qemu driver fails to verify that the PCI BAR0 size matches the expected CIRRUS VRAM SIZE (4 MB) during the PCI probe process. If a PCI device with a BAR0 smaller than 4 MB is used, the mapped VRAM becomes smaller than expected. Since validation checks assume a 4 MB VRAM, framebuffers larger than the actual mapped memory can be created. When the display plane is updated, the function cirrus primary plane helper atomic update() uses drm fb memcpy() to copy the framebuffer to VRAM, which can result in writing past the end of the mapped I/O memory and trigger a supervisor write page fault.
Recommendations Update the Linux kernel to a version where the cirrus pci probe() function validates that the PCI BAR0 resource is not smaller than CIRRUS VRAM SIZE.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98142

Affected Products

Linux Kernel