Database/Kernel, userspace & hypervisor
Linux kernel pmbus core: probing a VRM with more than 10 phases writes past the phase array
Impact
The PMBus core sized its per-page phase array for 10 phases, but the mp2975 driver already supports up to 14 phases per page and mp2856 up to 12, so probing those multiphase voltage-regulator controllers can write past the array. The patch raises the limit to 16 (and adds an output-voltage source mask) and is therefore a bug fix, not just preparation for new silicon. These MPS-class controllers sit on CPU and accelerator baseboards, so the exposure is slab corruption during driver probe - at boot or on hwmon module load - on affected boards. Nothing here is attacker-controlled: the trigger is the hardware that is present, which makes it read as unexplained instability rather than an attack.
Who can reach it
No attacker required - the host kernel probing an affected PMBus controller is the trigger. A local root user could force it by binding or rebinding the mp2975/mp2856 hwmon driver. No unprivileged or remote path.
What to do
Update to a stable kernel carrying the fix (commits linked in the record) and reboot, scheduling it with your normal kernel maintenance since the fault is at probe time. If you do not need PMBus telemetry from these regulators, blacklisting the mp2975/mp2856 hwmon drivers avoids the probe path until then. No vendor advisory or fixed distribution version is in the record.
References
Related entries
- Linux kernel trusted keys: TPM2 key load bounds-checks against the wrong blob lengthCVE-2026-98221 · Linux kernel trusted keys (TPM2 tpm2_load_cmd blob bounds)Unscored
- Linux kernel encrypted keys: u16 truncation of datablob_len gives a slab out-of-bounds writeCVE-2026-98222 · Linux kernel KEYS subsystem (encrypted keys, encrypted_key_alloc)Unscored
- Linux kernel SCSI core: unvalidated MODE SENSE lengths leak stack memory to the storage deviceCVE-2026-98232 · Linux kernel SCSI core (scsi_cdl_enable MODE SENSE length validation)Unscored
- Linux kernel dma-buf: 32-bit mapped_len truncates peer-to-peer DMA mappings larger than 4 GiBCVE-2026-98242 · Linux kernel dma-buf (phys vec to scatterlist conversion, mapped_len overflow)Unscored
- Linux kernel dma-fence: lost RCU protection after signalling allows use-after-free of fence name stringsCVE-2026-98243 · Linux kernel dma-buf/dma-fence (timeline and driver name accessors)Unscored
- Linux kernel arm64: LSE percpu ops on 8/16-bit types read and write 32 bits of memoryCVE-2026-98248 · Linux kernel arm64 percpu operations (LSE atomics on 8- and 16-bit types)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.