CVE-2026-98262
Received
Received - Intake
ata: libahci PxCLBU and PxFBU Clear for 32-bit DMA in Linux Kernel
Vulnerability report for CVE-2026-98262, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for
JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board.
The failure is seen as soon as the ahci driver is probed, and booting with
iommu=off does not solve the problem.
Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0'
for HBAs that do not support 64-bit addressing.
For HBAs that do support 64-bit addressing, the registers are read write,
with a reset value that is Implementation Specific.
When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit
addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64.
Thus, in this case, we need to explicitly clear the registers to 0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c |
| Linux | Linux | 2.6.22 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |