CVE-2026-98272
net: mvpp2: prevent buffer overflow in page_pool allocation
Description
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE.
INFO
Published Date :
Oct. 6, 2026, 9:18 a.m.
Last Modified :
Oct. 6, 2026, 9:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Verify hardware version is MVPP22 or newer.
- Ensure pool count does not exceed MVPP2_BM_MAX_POOLS.
- Apply updates to kernel network driver.
- Avoid per-CPU mode when limits are exceeded.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-98272.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-98272 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-98272
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-98272 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-98272 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Oct. 06, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE. Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/98xxx/CVE-2026-98272.json">CVE-2026-98272</a> Added Reference https://git.kernel.org/stable/c/14cb1e7702e5cb3c58888f6aed498381a73927d2 Added Reference https://git.kernel.org/stable/c/1734c3fc0066e228ce1c11e434b7c2527f0a949a Added Reference https://git.kernel.org/stable/c/4ac1d5adc4f4dbafbfd270b55cc6d8bf9849d545 Added Reference https://git.kernel.org/stable/c/5cefdb7acfc646fbded59ae77dfe0aac4c9e4a3c Added Reference https://git.kernel.org/stable/c/6569fd85b0ef9a8a6f20b7eb868420b8c7c0c2a0 Added Reference https://git.kernel.org/stable/c/dfd46b5584a5881b131008767950e1ab82713c8c Added Reference https://git.kernel.org/stable/c/e7f30dcfa6c64033bf9137362517bd248e5be384 Added Reference https://git.kernel.org/stable/c/f0e7d62c1eb984dd204095118973c59604144cd8