CVE-2026-98262: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board. The failure is seen as soon as the ahci driver is probed, and booting with iommu=off does not solve the problem. Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0' for HBAs that do not support 64-bit addressing. For HBAs that do support 64-bit addressing, the registers are read write, with a reset value that is Implementation Specific. When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64. Thus, in this case, we need to explicitly clear the registers to 0.
Affected products
- Linux Linux: from 2.6.22, before 5.10.271 (fixed in 5.10.271); from 5.11, before 5.15.222 (fixed in 5.15.222); from 5.16, before 6.1.189 (fixed in 6.1.189); from 6.2, before 6.6.158 (fixed in 6.6.158); from 6.7, before 6.12.112 (fixed in 6.12.112); from 6.13, before 6.18.54 (fixed in 6.18.54); …
Published 2026-10-06. Last modified 2026-10-06.