CVE-2026-98248

Source
https://cve.org/CVERecord?id=CVE-2026-98248
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98248.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98248
Downstream
Published
2026-10-06T08:45:16Z
Modified
2026-10-07T02:47:30Z
Summary
arm64: percpu: Fix LSE operations on {8,16}-bit types
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: percpu: Fix LSE operations on {8,16}-bit types

The assembly for _percpu##name##case##sz() and _percpu##name##return_case##sz() doesn't use the 'sfx' macro argument to form the LSE instruction. Without 'sfx', a W register argument will imply a 32-bit memory location, and consequently {8,16}-bit ops will erroneously read and write 32 bits of memory when the LSE instruction is used.

Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is a register-register operation which does not access memory (and does not take a size suffix).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98248.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
959bf2fd03b59fc107584c21425f3dc73c49f762
Fixed
d69ab4480e49bf925f4781afcc9f284affcb96b6
Fixed
390742871a723b52de9b92a94c0d1c85a2531e3e
Fixed
843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003
Fixed
8cf2093f5372952a9ebc805c418d45df7112cd14

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98248.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98248.json"