---
id: CVE-2026-98204
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()

  When chunking writes into SMBus blocks in rmi_smb_write_block(), the
  loop calculates block_len using…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()

  When chunking writes into SMBus blocks in rmi_smb_write_block(), the
  loop calculates block_len using…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    d01337c0892d1509500c727edf81380777c2dd0f
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    29fbcf5834f0a7f74bfd017c07da2411b35a4e2a
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    50dd585bee7669eb165e5defcc35d17f3822cfbb
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    e022538e13dd1c82af5ec25ac28f12ca0ab26160
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    dc05ec97b8299e48e31367a9bc412c7e9c0e2b42
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    9f0ce5e162eed8b68345abe839c59768bc60f99a
  - >-
    Linux >= 82264d0cf7aef2247563c031ff2ab96579d5d0cc <
    51cfe54f815ae175c7d1126b983d4d7c89715004
  - Linux 4.10
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:06.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98204'
references:
  - url: 'https://git.kernel.org/stable/c/29fbcf5834f0a7f74bfd017c07da2411b35a4e2a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/50dd585bee7669eb165e5defcc35d17f3822cfbb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/51cfe54f815ae175c7d1126b983d4d7c89715004'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9f0ce5e162eed8b68345abe839c59768bc60f99a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d01337c0892d1509500c727edf81380777c2dd0f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc05ec97b8299e48e31367a9bc412c7e9c0e2b42'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e022538e13dd1c82af5ec25ac28f12ca0ab26160'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.446Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()

When chunking writes into SMBus blocks in rmi_smb_write_block(), the
loop calculates block_len using the original total length (len) instead
of the remaining length (cur_len).

If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32
for every iteration, even on the final partial chunk where fewer than 32
bytes remain. This causes smb_block_write() to read 32 bytes from the
advanced data buffer pointer, reading past the end of the input buffer.

Fix this by calculating block_len using cur_len and advancing the buffer
and address pointers by block_len.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
