CVE-2026-98199

Source
https://cve.org/CVERecord?id=CVE-2026-98199
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98199.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98199
Downstream
Published
2026-10-06T08:44:37Z
Modified
2026-10-08T02:52:54Z
Summary
hwmon: (pmbus/core) increase number of phases and add new mask
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus/core) increase number of phases and add new mask

Increase the number of phases to 16 as a new upcoming device supports such a number.

While at it, add a new mask for controlling the source of the output voltage.

Note (groeck):

This patch was meant to prepare for support of MAX20826 and compatible devices, which support more than 10 phases per page. However, Sashiko reports that the mp2975 driver already supports up to 14 phases, and the mp2856 driver supports up to 12 phases. This already has the potential for out-of-bounds writes when probing the affected chips, making this patch a bug fix.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98199.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2c6fcbb211494f1ff6ef384776944b9e04f4c14c
Fixed
272006a52cbd9c8342cead4d3eb9221ebbe8b985
Fixed
b32607710a20ad983f9fe4a3051892584c0641a4
Fixed
66368f682a53f3a3842e20eebb571a59809c52c0
Fixed
1ec644c94466834f8cb6b7ba12636fd047bdfdda
Fixed
9558fc1e042ac6b12dd63c37d2c51be4ec86d402
Fixed
b49f100a15b8876deccf8c59f41af92b8e25fd74
Fixed
06bd6794b5fd2163880ac3bfe973d4cc61f359f3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98199.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98199.json"