GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel pmbus core: probing a VRM with more than 10 phases writes past the phase array

UnscoredCVE-2026-98199Kernel, userspace & hypervisorcurated

Impact

The PMBus core sized its per-page phase array for 10 phases, but the mp2975 driver already supports up to 14 phases per page and mp2856 up to 12, so probing those multiphase voltage-regulator controllers can write past the array. The patch raises the limit to 16 (and adds an output-voltage source mask) and is therefore a bug fix, not just preparation for new silicon. These MPS-class controllers sit on CPU and accelerator baseboards, so the exposure is slab corruption during driver probe - at boot or on hwmon module load - on affected boards. Nothing here is attacker-controlled: the trigger is the hardware that is present, which makes it read as unexplained instability rather than an attack.

Who can reach it

No attacker required - the host kernel probing an affected PMBus controller is the trigger. A local root user could force it by binding or rebinding the mp2975/mp2856 hwmon driver. No unprivileged or remote path.

What to do

Update to a stable kernel carrying the fix (commits linked in the record) and reboot, scheduling it with your normal kernel maintenance since the fault is at probe time. If you do not need PMBus telemetry from these regulators, blacklisting the mp2975/mp2856 hwmon drivers avoids the probe path until then. No vendor advisory or fixed distribution version is in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.