Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98199— hwmon: (pmbus/core) increase number of phases and add new mask

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: hwmon: (pmbus/core) 增加相位数量并添加新掩码 将相位数量增加到 16,以支持一款即将推出的支持该数量的设备。 同时,添加了一个用于控制输出电压来源的新掩码。 注意(groeck): 此补丁旨在为 MAX20826 及兼容设备提供支持做准备,这些设备每页支持超过 10 个相位。然而,Sashiko 报告称,mp2975 驱动程序已支持最多 14 个相位,而 mp2856 驱动程序支持最多 12 个相位。这已经存在探测受影响芯片时越界写入的潜在风险,因此

AI Predicted 5.5 Difficulty: Hard EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 2c6fcbb211494f1ff6ef384776944b9e04f4c14c< 272006a52cbd9c8342cead4d3eb9221ebbe8b985 affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< b32607710a20ad983f9fe4a3051892584c0641a4 affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< 66368f682a53f3a3842e20eebb571a59809c52c0 affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< 1ec644c94466834f8cb6b7ba12636fd047bdfdda affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< 9558fc1e042ac6b12dd63c37d2c51be4ec86d402 affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< b49f100a15b8876deccf8c59f41af92b8e25fd74 affected
2c6fcbb211494f1ff6ef384776944b9e04f4c14c< 06bd6794b5fd2163880ac3bfe973d4cc61f359f3 affected
5.10 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98199

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
hwmon: (pmbus/core) increase number of phases and add new mask
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) increase number of phases and add new mask Increase the number of phases to 16 as a new upcoming device supports such a number. While at it, add a new mask for controlling the source of the output voltage. Note (groeck): This patch was meant to prepare for support of MAX20826 and compatible devices, which support more than 10 phases per page. However, Sashiko reports that the mp2975 driver already supports up to 14 phases, and the mp2856 driver supports up to 12 phases. This already has the potential for out-of-bounds writes when probing the affected chips, making this patch a bug fix.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 2c6fcbb211494f1ff6ef384776944b9e04f4c14c ~ 272006a52cbd9c8342cead4d3eb9221ebbe8b985 -
Linux Linux 5.10 -

II. Public POCs for CVE-2026-98199

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98199

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98199 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98199

No comments yet


Leave a comment