Out-of-Bounds Read Vulnerability in Linux Kernel Affecting QAIC Acceleration
CVE-2026-98155
What is CVE-2026-98155?
A vulnerability in the Linux kernel's QAIC acceleration module could allow for an out-of-bounds read due to insufficient bounds checking in the resp_worker function. This vulnerability is especially concerning as it could result in reading beyond allocated memory, leading to potential system crashes or infinite loops. The issue arises when a malformed wire message is received from a device, exploiting the flaw made evident by commit 2feec5ae5df7. The solution integrates existing bounds checking mechanisms within the decoding process, thereby mitigating the risk of maladaptive behavior during message processing.
Affected Version(s)
Linux 08021f2d4a557d6491e3bcc288e96425f50aa3cf
Linux f403094d9075d7c565a3d81002b781c325cb3c07 < 12deeade460d47031267256ba07add51cc7eabd0
Linux 2feec5ae5df785658924ab6bd91280dc3926507c