GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel arm64: LSE percpu ops on 8/16-bit types read and write 32 bits of memory

UnscoredCVE-2026-98248Kernel, userspace & hypervisorcurated

Impact

The arm64 percpu macros omit the size suffix when forming the LSE instruction, so a W register operand implies a 32-bit access and every 8-bit or 16-bit percpu operation touches four bytes instead of one or two. On any arm64 CPU with LSE atomics - which is every datacenter-class Arm part, including the Arm hosts in Grace and GH200/GB200 systems - this silently corrupts whatever percpu state sits next to the intended variable. The consequence is corrupted kernel per-CPU data with no attacker action required, which shows up as misbehaviour or crashes rather than as a clean fault. The record is a stable-tree correctness fix with no CVSS score and no exploitation detail; x86 nodes are not affected.

Who can reach it

Not an attacker-reachable interface - it is a miscompiled instruction sequence that fires during normal kernel operation on arm64 hosts built with LSE atomics. Exposure is the node itself, not a tenant or a network path.

What to do

On arm64 nodes, take the stable kernel update that appends the size suffix to the LSE instruction, then drain and reboot each node. x86_64 fleets need no action. The record names only the stable commits, not a fixed release version.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.