CVE-2026-98363
Received Received - Intake

Buffer Overflow in Linux Kernel SCPI DVFS Firmware

Vulnerability report for CVE-2026-98363, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB). The missing upper bound dates back to the original SCPI DVFS support. Reject zero and out-of-range counts in one check and return -EINVAL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux Linux 4.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's firmware handling for ARM SCPI (System Control and Power Interface). It involves a missing check for the number of DVFS (Dynamic Voltage and Frequency Scaling) OPPs (Operating Performance Points) received from firmware. The function scpi_dvfs_get_info() did not validate if the OPP count exceeded the maximum allowed, leading to potential out-of-bounds memory access when processing firmware responses.

Detection Guidance

This vulnerability affects the Linux kernel's SCPI DVFS implementation. Detection requires checking kernel logs for SCPI-related errors or examining the firmware interface for invalid DVFS OPP counts. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker with access to the system firmware to cause memory corruption or crashes by providing an invalid OPP count. This might lead to denial-of-service conditions or unexpected system behavior. Systems using ARM-based processors with SCPI firmware are affected.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for this vulnerability. Monitor kernel logs for SCPI errors and ensure firmware adheres to MAX_DVFS_OPPS limits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98363. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart