CVE-2026-98363

Source
https://cve.org/CVERecord?id=CVE-2026-98363
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98363.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98363
Downstream
Published
2026-10-06T08:46:49Z
Modified
2026-10-08T02:52:58Z
Summary
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
Details

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS

scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB). The missing upper bound dates back to the original SCPI DVFS support.

Reject zero and out-of-range counts in one check and return -EINVAL.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98363.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Fixed
e9887eeaa138c6b5697af3d2f7c71dc82407b154
Fixed
1aadbef648e92ca642125f188f99b0a26628e3ba
Fixed
7daaa684097377b66b98a832de307688a7f3bbc7
Fixed
f17865332cc4ceaac846bcd7c28badbaedfabeff
Fixed
0130f9ad3974a5b2ad0fa03d0b300a9fb83ed901
Fixed
69ec03cd481973e4be44a7158ed6c0fa06a9a5f9
Fixed
cc563a59aded6f3b02d75dcc3c0bc5e90755d99e
Fixed
32471d84a487c7fd74532bc96be56f8028cf4a3f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98363.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98363.json"