---
id: CVE-2026-98203
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: soc_button_array - check btns_desc->package.count

  Check that btns_desc->package.count is not 0 before accessing
  btns_desc->package.elements[0].
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: soc_button_array - check btns_desc->package.count

  Check that btns_desc->package.count is not 0 before accessing
  btns_desc->package.elements[0].
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    c3a94bfedfa2e4c4d37d1181e8db1ab010f1321a
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    ec0576dabd6bf4f6532c5f0a58c9bf57095e45a4
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    c62c6944c680bc4ae188ca9045daada32fcd10ec
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    42c7afc0e5f5b5e12e9689e9a9815b5824cf0efb
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    eb5563386fb8c5dbb55d902a71a0ce10e4f307eb
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    8a70a192e3e5b3ccbeeaf149c931cf45b8e82155
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    12d80e6351556cfecbdd09416e5e4c73d6ca08ba
  - >-
    Linux >= 4c3362f44980aba8e1e69cd6970effbd9f17dc69 <
    fb5022278b6ea7f1838e3ef78028d5d5e3375f65
  - Linux 4.12
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:06.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98203'
references:
  - url: 'https://git.kernel.org/stable/c/12d80e6351556cfecbdd09416e5e4c73d6ca08ba'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/42c7afc0e5f5b5e12e9689e9a9815b5824cf0efb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8a70a192e3e5b3ccbeeaf149c931cf45b8e82155'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c3a94bfedfa2e4c4d37d1181e8db1ab010f1321a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c62c6944c680bc4ae188ca9045daada32fcd10ec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb5563386fb8c5dbb55d902a71a0ce10e4f307eb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ec0576dabd6bf4f6532c5f0a58c9bf57095e45a4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb5022278b6ea7f1838e3ef78028d5d5e3375f65'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.446Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Input: soc_button_array - check btns_desc->package.count

Check that btns_desc->package.count is not 0 before accessing
btns_desc->package.elements[0].

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
