CVE-2026-98272
Received Received - Intake

Buffer Overflow in Linux Kernel mvpp2 Driver

Vulnerability report for CVE-2026-98272, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 7d04b0b13b1175ce0c4bdc77f1278c1f120f874f
Linux Linux 5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a buffer overflow vulnerability in the Linux kernel's mvpp2 network driver. It occurs when the number of receive queues (nrxqs) multiplied by 2 exceeds the maximum allowed pools (MVPP2_BM_MAX_POOLS=8). The issue arises in mvpp2_change_mtu() which calls mvpp2_bm_switch_buffers() without checking array bounds, potentially accessing memory outside priv->page_pool array.

Impact Analysis

This could lead to system crashes, data corruption, or privilege escalation if exploited. Systems using affected Linux kernel versions with mvpp2 network interfaces may be vulnerable to memory corruption attacks.

Mitigation Strategies

Update the Linux kernel to a patched version that resolves the mvpp2 buffer overflow issue. Ensure the hardware version is MVPP22 or newer and verify that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8) before enabling per-CPU buffering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98272. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart