HIGH Introduced in 5.0
arm64 Percpu LSE OOB
CVE-2026-98248
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: arm64: percpu: Fix LSE operations on {8,16}-bit types The assembly for __percpu_##name##_case_##sz() and __percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro argument to form the LSE instruction. Without 'sfx', a W register argument will imply a 32-bit memory location, and consequently {8,16}-bit ops will erroneously read and write 32 bits of memory when the LSE instruction is used. Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is a register-register operation which does not access memory (and does not take a size suffix).
02KernelScan AI Analysis
Risk summary
On ARM64 systems with LSE atomics, percpu atomic operations on 8-bit and 16-bit types incorrectly access 32 bits of memory, corrupting adjacent percpu variables. Any local user can trigger this through normal system activity on affected hardware, potentially leading to kernel memory corruption, information disclosure, or denial of service.
Vulnerability analysis
On ARM64 systems equipped with LSE atomic instructions, the kernel's percpu atomic operation macros for 8-bit and 16-bit types omit the instruction size suffix when emitting LSE instructions. Without the suffix, the assembler defaults to 32-bit memory accesses, causing each 8-bit or 16-bit percpu atomic operation to read and write 32 bits of memory instead of the intended width. This corrupts adjacent percpu variables on the same CPU with every such operation. The fix adds the size suffix to the LSE instruction so that the memory access width matches the operation's type size. Any local user on an affected ARM64 system with LSE support can trigger this through ordinary syscalls that exercise percpu atomic operations, which are used widely across the kernel.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.0 | 6.12.112 | d69ab4480e49 |
| 6.18 | 5.0 | 6.18.54 | 390742871a72 |
| 7.2 | 5.0 | 7.2.8 | 843ace1d0a39 |
| mainline | 5.0 | 7.3-rc4 | 8cf2093f5372 |