GHSA-P97V-423W-MPCQ
Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31In the Linux kernel, the following vulnerability has been resolved:
arm64: percpu: Fix LSE operations on {8,16}-bit types
The assembly for __percpu_##name##case##sz() and __percpu_##name##return_case##sz() doesn't use the 'sfx' macro argument to form the LSE instruction. Without 'sfx', a W register argument will imply a 32-bit memory location, and consequently {8,16}-bit ops will erroneously read and write 32 bits of memory when the LSE instruction is used.
Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is a register-register operation which does not access memory (and does not take a size suffix).
{
"affected": [],
"aliases": [
"CVE-2026-98248"
],
"database_specific": {
"cwe_ids": [],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-06T09:18:13Z",
"severity": null
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: percpu: Fix LSE operations on {8,16}-bit types\n\nThe assembly for __percpu_##name##_case_##sz() and\n__percpu_##name##_return_case_##sz() doesn\u0027t use the \u0027sfx\u0027 macro\nargument to form the LSE instruction. Without \u0027sfx\u0027, a W register\nargument will imply a 32-bit memory location, and consequently\n{8,16}-bit ops will erroneously read and write 32 bits of memory when\nthe LSE instruction is used.\n\nFix this by appending \u0027sfx\u0027 to \u0027op_lse\u0027 to LSE instruction. It is not\nnecessary (and not valid) to append \u0027sfx\u0027 to \u0027op_llsc\u0027, as \u0027op_llsc\u0027 is\na register-register operation which does not access memory (and does not\ntake a size suffix).",
"id": "GHSA-p97v-423w-mpcq",
"modified": "2026-10-06T09:31:32Z",
"published": "2026-10-06T09:31:32Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98248"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/390742871a723b52de9b92a94c0d1c85a2531e3e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8cf2093f5372952a9ebc805c418d45df7112cd14"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d69ab4480e49bf925f4781afcc9f284affcb96b6"
}
],
"schema_version": "1.4.0",
"severity": []
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.