{"id":"CVE-2026-98204","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()\n\nWhen chunking writes into SMBus blocks in rmi_smb_write_block(), the\nloop calculates block_len using…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()\n\nWhen chunking writes into SMBus blocks in rmi_smb_write_block(), the\nloop calculates block_len using…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < d01337c0892d1509500c727edf81380777c2dd0f","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < 7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < 29fbcf5834f0a7f74bfd017c07da2411b35a4e2a","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < 50dd585bee7669eb165e5defcc35d17f3822cfbb","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < e022538e13dd1c82af5ec25ac28f12ca0ab26160","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < dc05ec97b8299e48e31367a9bc412c7e9c0e2b42","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < 9f0ce5e162eed8b68345abe839c59768bc60f99a","Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc < 51cfe54f815ae175c7d1126b983d4d7c89715004","Linux 4.10"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:06.383","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98204","references":[{"url":"https://git.kernel.org/stable/c/29fbcf5834f0a7f74bfd017c07da2411b35a4e2a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50dd585bee7669eb165e5defcc35d17f3822cfbb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51cfe54f815ae175c7d1126b983d4d7c89715004","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f0ce5e162eed8b68345abe839c59768bc60f99a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d01337c0892d1509500c727edf81380777c2dd0f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc05ec97b8299e48e31367a9bc412c7e9c0e2b42","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e022538e13dd1c82af5ec25ac28f12ca0ab26160","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.446Z","slug":"CVE-2026-98204","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nInput: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()\n\nWhen chunking writes into SMBus blocks in rmi_smb_write_block(), the\nloop calculates block_len using the original total length (len) instead\nof the remaining length (cur_len).\n\nIf len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32\nfor every iteration, even on the final partial chunk where fewer than 32\nbytes remain. This causes smb_block_write() to read 32 bytes from the\nadvanced data buffer pointer, reading past the end of the input buffer.\n\nFix this by calculating block_len using cur_len and advancing the buffer\nand address pointers by block_len.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}