Bug 2546398 (CVE-2026-98204) - CVE-2026-98204 kernel: Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
Summary: CVE-2026-98204 kernel: Input: rmi_smbus - fix out-of-bounds read in rmi_smb_w...
Keywords:
Status: NEW
Alias: CVE-2026-98204
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:14 UTC by OSIDB Bzimport
Modified: 2026-10-09 08:23 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:14:18 UTC
In the Linux kernel, the following vulnerability has been resolved:

Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()

When chunking writes into SMBus blocks in rmi_smb_write_block(), the
loop calculates block_len using the original total length (len) instead
of the remaining length (cur_len).

If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32
for every iteration, even on the final partial chunk where fewer than 32
bytes remain. This causes smb_block_write() to read 32 bytes from the
advanced data buffer pointer, reading past the end of the input buffer.

Fix this by calculating block_len using cur_len and advancing the buffer
and address pointers by block_len.


Note You need to log in before you can comment on or make changes to this bug.