Answer in brief
CVE-2026-98272 records a Unknown severity vulnerability in net: mvpp2: prevent buffer overflow in page_pool allocation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545 || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <dfd46b5584a5881b131008767950e1ab82713c8c || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0 || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <e7f30dcfa6c64033bf9137362517bd248e5be384 || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <f0e7d62c1eb984dd204095118973c59604144cd8 || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <1734c3fc0066e228ce1c11e434b7c2527f0a949a || >=7d04b0b13b1175ce0c4bdc77f1278c1f120f874f <14cb1e7702e5cb3c58888f6aed498381a73927d2 | 5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c, 4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545, dfd46b5584a5881b131008767950e1ab82713c8c, 6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0, e7f30dcfa6c64033bf9137362517bd248e5be384, f0e7d62c1eb984dd204095118973c59604144cd8, 1734c3fc0066e228ce1c11e434b7c2527f0a949a, 14cb1e7702e5cb3c58888f6aed498381a73927d2 |
| Linux/Linuxgeneric | 5.4 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Quoted source text, attributed separately from HOL analysis.