Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98272— net: mvpp2: prevent buffer overflow in page_pool allocation

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 网络子系统:mvpp2:防止 page_pool 分配中的缓冲区溢出 仅当池的数量(nrxqs 2)不超过 MVPP2_BM_MAX_POOLS(8)时,才支持每处理器缓冲方案。在初始启用 percpu_pools 时,mvpp2_probe() 中已对此进行检查。 然而,mvpp2_change_mtu() 随后可能调用 mvpp2_bm_switch_buffers(priv, true),而未进行此检查,这可能导致在 mvpp2_bm_init() 中对 priv->

AI Predicted 7.8 Difficulty: Hard EPSS 0.20% · P9

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< 5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< 4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545 affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< dfd46b5584a5881b131008767950e1ab82713c8c affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< 6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0 affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< e7f30dcfa6c64033bf9137362517bd248e5be384 affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< f0e7d62c1eb984dd204095118973c59604144cd8 affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< 1734c3fc0066e228ce1c11e434b7c2527f0a949a affected
7d04b0b13b1175ce0c4bdc77f1278c1f120f874f< 14cb1e7702e5cb3c58888f6aed498381a73927d2 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98272

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: mvpp2: prevent buffer overflow in page_pool allocation
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f ~ 5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c -
Linux Linux 5.4 -

II. Public POCs for CVE-2026-98272

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98272

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98272 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98272

No comments yet


Leave a comment