Answer in brief
CVE-2026-98157 records a Unknown severity vulnerability in EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e27e3dac651771fe3250f6305dee277bce29fc5d <ea01c061d839b520f385f112908de1c6e3391327 || >=e27e3dac651771fe3250f6305dee277bce29fc5d <528052af901d6e6bbfa0e52362a70a58a5dd1e43 || >=e27e3dac651771fe3250f6305dee277bce29fc5d <0e022ee4f8e0dc843ba4c80bb75408a7704279af || >=e27e3dac651771fe3250f6305dee277bce29fc5d <66cc9dec919dd63d8e4b3d386f7aed3ae684e645 | ea01c061d839b520f385f112908de1c6e3391327, 528052af901d6e6bbfa0e52362a70a58a5dd1e43, 0e022ee4f8e0dc843ba4c80bb75408a7704279af, 66cc9dec919dd63d8e4b3d386f7aed3ae684e645 |
| Linux/Linuxgeneric | 2.6.23 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation The poll_msec sysfs store file uses simple_strtoul() which accepts an unsigned long, but the target field (poll_msec) is unsigned int. On 64-bit systems, a value > UINT_MAX is silently truncated when stored. Fix the mismatch by using kstrtouint() instead. This rejects values larger than UINT_MAX at parse time, making truncation impossible. Also add a check for value < 1 to reject the 0-delay case, which would cause the poll work to spin without delay and consume 100% CPU.
Quoted source text, attributed separately from HOL analysis.