{"id":"CVE-2026-98204","summary":"Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()\n\nWhen chunking writes into SMBus blocks in rmi_smb_write_block(), the\nloop calculates block_len using the original total length (len) instead\nof the remaining length (cur_len).\n\nIf len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32\nfor every iteration, even on the final partial chunk where fewer than 32\nbytes remain. This causes smb_block_write() to read 32 bytes from the\nadvanced data buffer pointer, reading past the end of the input buffer.\n\nFix this by calculating block_len using cur_len and advancing the buffer\nand address pointers by block_len.","modified":"2026-10-08T02:52:53.060489280Z","published":"2026-10-06T08:44:41.712Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98204.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/29fbcf5834f0a7f74bfd017c07da2411b35a4e2a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/50dd585bee7669eb165e5defcc35d17f3822cfbb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/51cfe54f815ae175c7d1126b983d4d7c89715004"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9f0ce5e162eed8b68345abe839c59768bc60f99a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d01337c0892d1509500c727edf81380777c2dd0f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dc05ec97b8299e48e31367a9bc412c7e9c0e2b42"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e022538e13dd1c82af5ec25ac28f12ca0ab26160"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98204.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98204"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"82264d0cf7aef2247563c031ff2ab96579d5d0cc"},{"fixed":"d01337c0892d1509500c727edf81380777c2dd0f"},{"fixed":"7c800af1c6030a5f27d46ce7d6d5d75f9c1efaf8"},{"fixed":"29fbcf5834f0a7f74bfd017c07da2411b35a4e2a"},{"fixed":"50dd585bee7669eb165e5defcc35d17f3822cfbb"},{"fixed":"e022538e13dd1c82af5ec25ac28f12ca0ab26160"},{"fixed":"dc05ec97b8299e48e31367a9bc412c7e9c0e2b42"},{"fixed":"9f0ce5e162eed8b68345abe839c59768bc60f99a"},{"fixed":"51cfe54f815ae175c7d1126b983d4d7c89715004"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98204.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98204.json"}}],"schema_version":"1.9.0"}