Answer in brief
CVE-2026-98204 records a Unknown severity vulnerability in Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <d01337c0892d1509500c727edf81380777c2dd0f || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8 || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <29fbcf5834f0a7f74bfd017c07da2411b35a4e2a || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <50dd585bee7669eb165e5defcc35d17f3822cfbb || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <e022538e13dd1c82af5ec25ac28f12ca0ab26160 || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <dc05ec97b8299e48e31367a9bc412c7e9c0e2b42 || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <9f0ce5e162eed8b68345abe839c59768bc60f99a || >=82264d0cf7aef2247563c031ff2ab96579d5d0cc <51cfe54f815ae175c7d1126b983d4d7c89715004 | d01337c0892d1509500c727edf81380777c2dd0f, 7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8, 29fbcf5834f0a7f74bfd017c07da2411b35a4e2a, 50dd585bee7669eb165e5defcc35d17f3822cfbb, e022538e13dd1c82af5ec25ac28f12ca0ab26160, dc05ec97b8299e48e31367a9bc412c7e9c0e2b42, 9f0ce5e162eed8b68345abe839c59768bc60f99a, 51cfe54f815ae175c7d1126b983d4d7c89715004 |
| Linux/Linuxgeneric | 4.10 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() When chunking writes into SMBus blocks in rmi_smb_write_block(), the loop calculates block_len using the original total length (len) instead of the remaining length (cur_len). If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32 for every iteration, even on the final partial chunk where fewer than 32 bytes remain. This causes smb_block_write() to read 32 bytes from the advanced data buffer pointer, reading past the end of the input buffer. Fix this by calculating block_len using cur_len and advancing the buffer and address pointers by block_len.
Quoted source text, attributed separately from HOL analysis.