Answer in brief
CVE-2026-98248 records a Unknown severity vulnerability in arm64: percpu: Fix LSE operations on {8,16}-bit types. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=959bf2fd03b59fc107584c21425f3dc73c49f762 <d69ab4480e49bf925f4781afcc9f284affcb96b6 || >=959bf2fd03b59fc107584c21425f3dc73c49f762 <390742871a723b52de9b92a94c0d1c85a2531e3e || >=959bf2fd03b59fc107584c21425f3dc73c49f762 <843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003 || >=959bf2fd03b59fc107584c21425f3dc73c49f762 <8cf2093f5372952a9ebc805c418d45df7112cd14 | d69ab4480e49bf925f4781afcc9f284affcb96b6, 390742871a723b52de9b92a94c0d1c85a2531e3e, 843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003, 8cf2093f5372952a9ebc805c418d45df7112cd14 |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: arm64: percpu: Fix LSE operations on {8,16}-bit types The assembly for __percpu_##name##_case_##sz() and __percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro argument to form the LSE instruction. Without 'sfx', a W register argument will imply a 32-bit memory location, and consequently {8,16}-bit ops will erroneously read and write 32 bits of memory when the LSE instruction is used. Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is a register-register operation which does not access memory (and does not take a size suffix).
Quoted source text, attributed separately from HOL analysis.