CVE-2026-98155: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Address potential out-of-bounds read in resp_worker() Although 'commit 2feec5ae5df7 ("accel/qaic: Handle DBC deactivation if the owner went away")' fixes the scenario it was intended for by walking the message and only decoding QAIC_TRANS_DEACTIVATE_FROM_DEV, if present, it skipped over the bounds checking code that is included in decode_message(). This could lead to issues such as reading past the slab allocation's end, infinite loops or kernel panics. For those issues to happen, a malformed wire message is needed to be sent from the device. Instead of duplicating the bounds checking code already present in decode_message(), use the function inside resp_worker().
Affected products
- Linux Linux: from 6.6.134, before 6.6.158 (fixed in 6.6.158); from 6.12.81, before 6.12.111 (fixed in 6.12.111); from 6.18.22, before 6.18.53 (fixed in 6.18.53); from 6.19.12, before 6.20 (fixed in 6.20); from 7.0, before 7.2.7 (fixed in 7.2.7)
Published 2026-09-25. Last modified 2026-10-03.