KernelScan.io

HIGH Introduced in 5.0

arm64 Percpu LSE OOB

CVE-2026-98248

CVSS 7.8 / 10.0 KernelScan AI

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: arm64: percpu: Fix LSE operations on {8,16}-bit types The assembly for __percpu_##name##_case_##sz() and __percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro argument to form the LSE instruction. Without 'sfx', a W register argument will imply a 32-bit memory location, and consequently {8,16}-bit ops will erroneously read and write 32 bits of memory when the LSE instruction is used. Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is a register-register operation which does not access memory (and does not take a size suffix).

02

Engine v0.7.0

Risk summary

On ARM64 systems with LSE atomics, percpu atomic operations on 8-bit and 16-bit types incorrectly access 32 bits of memory, corrupting adjacent percpu variables. Any local user can trigger this through normal system activity on affected hardware, potentially leading to kernel memory corruption, information disclosure, or denial of service.

Affectedarch/arm64/include/asm/percpu.h (arm64 percpu)

Vulnerability analysis

On ARM64 systems equipped with LSE atomic instructions, the kernel's percpu atomic operation macros for 8-bit and 16-bit types omit the instruction size suffix when emitting LSE instructions. Without the suffix, the assembler defaults to 32-bit memory accesses, causing each 8-bit or 16-bit percpu atomic operation to read and write 32 bits of memory instead of the intended width. This corrupts adjacent percpu variables on the same CPU with every such operation. The fix adds the size suffix to the LSE instruction so that the memory access width matches the operation's type size. Any local user on an affected ARM64 system with LSE support can trigger this through ordinary syscalls that exercise percpu atomic operations, which are used widely across the kernel.

03

BranchIntroducedFixed inPatch commit
6.125.06.12.112d69ab4480e49
6.185.06.18.54390742871a72
7.25.07.2.8843ace1d0a39
mainline5.07.3-rc48cf2093f5372