---
id: CVE-2026-98248
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  arm64: percpu: Fix LSE operations on {8,16}-bit types

  The assembly for __percpu_##name##_case_##sz() and
  __percpu_##name##_return_case_##sz() doesn't use the 'sfx' mac…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  arm64: percpu: Fix LSE operations on {8,16}-bit types

  The assembly for __percpu_##name##_case_##sz() and
  __percpu_##name##_return_case_##sz() doesn't use the 'sfx' mac…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 959bf2fd03b59fc107584c21425f3dc73c49f762 <
    d69ab4480e49bf925f4781afcc9f284affcb96b6
  - >-
    Linux >= 959bf2fd03b59fc107584c21425f3dc73c49f762 <
    390742871a723b52de9b92a94c0d1c85a2531e3e
  - >-
    Linux >= 959bf2fd03b59fc107584c21425f3dc73c49f762 <
    843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003
  - >-
    Linux >= 959bf2fd03b59fc107584c21425f3dc73c49f762 <
    8cf2093f5372952a9ebc805c418d45df7112cd14
  - Linux 5.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:13.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98248'
references:
  - url: 'https://git.kernel.org/stable/c/390742871a723b52de9b92a94c0d1c85a2531e3e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/843ace1d0a39e9b1cfcbfb3856a7b0fbdd9cd003'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8cf2093f5372952a9ebc805c418d45df7112cd14'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d69ab4480e49bf925f4781afcc9f284affcb96b6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.433Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

arm64: percpu: Fix LSE operations on {8,16}-bit types

The assembly for __percpu_##name##_case_##sz() and
__percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro
argument to form the LSE instruction. Without 'sfx', a W register
argument will imply a 32-bit memory location, and consequently
{8,16}-bit ops will erroneously read and write 32 bits of memory when
the LSE instruction is used.

Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not
necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is
a register-register operation which does not access memory (and does not
take a size suffix).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
