Answer in brief
CVE-2026-98262 records a Unknown severity vulnerability in ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <0191c9ff23ef1678dbfb5ad253a2dee92feb5d71 || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <8f510f68208a1f673d7c7234a687be4671490e9c || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <4719424bb7cb9f20b73986bcb72dd528f0e5c6eb || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <a5a8b4737f68bbac8aa0685af0c8921e6003c22b || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <b28a17d4a9bb0aa38b48681c3927b012ba40eabe || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <b691a3e244278362e552439d6d3ee5a5d3703488 || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <7912ad8fb5233bb8cfe21d50df639c7f4854ff9d || >=c7a42156d99bcea7f8173ba7a6034bbaa2ecb77c <82e47533221d4746947b74d2e79a478c36c6433a | 0191c9ff23ef1678dbfb5ad253a2dee92feb5d71, 8f510f68208a1f673d7c7234a687be4671490e9c, 4719424bb7cb9f20b73986bcb72dd528f0e5c6eb, a5a8b4737f68bbac8aa0685af0c8921e6003c22b, b28a17d4a9bb0aa38b48681c3927b012ba40eabe, b691a3e244278362e552439d6d3ee5a5d3703488, 7912ad8fb5233bb8cfe21d50df639c7f4854ff9d, 82e47533221d4746947b74d2e79a478c36c6433a |
| Linux/Linuxgeneric | 2.6.22 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board. The failure is seen as soon as the ahci driver is probed, and booting with iommu=off does not solve the problem. Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0' for HBAs that do not support 64-bit addressing. For HBAs that do support 64-bit addressing, the registers are read write, with a reset value that is Implementation Specific. When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64. Thus, in this case, we need to explicitly clear the registers to 0.
Quoted source text, attributed separately from HOL analysis.