CVE-2026-98157: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98157 is an input validation flaw in the Linux kernel's EDAC (Error Detection and Correction) subsystem that can lead to a local denial of service. The vulnerability exists in the EDAC/device_sysfs component, where the poll_msec sysfs interface uses simple_strtoul() — which accepts unsigned long values — but stores the result in an unsigned int field, causing silent truncation on 64-bit systems for values exceeding UINT_MAX. Additionally, the absence of a lower-bound check allows a value of 0 to be written, causing the poll work queue to spin without delay and consume 100% CPU. The vulnerability affects Linux kernel versions from 2.6.23 through multiple stable branches, with fixes available in versions 6.12.111, 6.18.53, 7.2.7, and 7.3-rc2. It was disclosed on September 25, 2026, and carries an estimated CVSS severity of Medium with an EPSS score of 0.0 (Github Advisory, Feedly).

Technical details

The root cause is improper input validation (related to CWE-20) in the poll_msec sysfs store handler within EDAC/device_sysfs. The handler calls simple_strtoul(), which parses values as unsigned long; on 64-bit Linux systems, unsigned long is 64 bits while unsigned int is 32 bits, so values greater than UINT_MAX (4,294,967,295) are silently truncated when assigned to the poll_msec field, resulting in unexpected polling intervals. A second issue is the lack of a minimum value check: writing 0 to the sysfs file causes the EDAC poll work to reschedule itself with zero delay, creating a tight busy-loop that saturates a CPU core. Exploitation requires local access and write permissions to /sys/devices/system/edac/*/poll_msec. The fix replaces simple_strtoul() with kstrtouint(), which rejects out-of-range values at parse time, and adds a value < 1 guard (Github Advisory).

Impact

The primary impact is a local denial of service: a user with write access to the EDAC sysfs interface can cause a CPU core to spin at 100% utilization indefinitely by writing a zero value to poll_msec, degrading system performance and potentially affecting availability of services running on the host. On 64-bit systems, writing values larger than UINT_MAX results in silent truncation, leading to unpredictable EDAC polling behavior that could mask hardware memory errors. There is no evidence of confidentiality or integrity impact beyond the availability disruption (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is locally exploitable only, requiring write access to the EDAC sysfs file, which limits the attack surface to privileged or specially configured local users. The EPSS score is 0.0, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Github Advisory, Feedly).

Exploitation steps

  1. Gain local access: Obtain a local shell on a 64-bit Linux system running a vulnerable kernel (2.6.23 through the unpatched stable branches) with the EDAC subsystem enabled.
  2. Verify sysfs access: Confirm write access to the EDAC poll_msec sysfs file, e.g., ls -la /sys/devices/system/edac/*/poll_msec.
  3. Trigger CPU spin (DoS): Write a zero value to the sysfs file to cause the poll work to reschedule without delay: echo 0 > /sys/devices/system/edac/<device>/poll_msec. This causes the EDAC poll work queue to spin continuously, consuming 100% of a CPU core.
  4. Alternative — truncation abuse: On a 64-bit system, write a value exceeding UINT_MAX (e.g., echo 4294967296 > /sys/devices/system/edac/<device>/poll_msec) to cause silent truncation, resulting in an unexpected polling interval (e.g., 0 or 1 ms) that may mask hardware memory error detection (Github Advisory).

Indicators of compromise

  • File System: Unexpected writes to /sys/devices/system/edac/*/poll_msec with values of 0 or values exceeding 4294967295.
  • Process/CPU: Sustained 100% CPU utilization on a single core attributable to a kernel worker thread (visible via top or perf), particularly a work queue thread associated with EDAC polling.
  • Logs: Kernel log entries (via dmesg) showing abnormal EDAC polling behavior or repeated EDAC work queue scheduling at unusually high frequency.

Mitigation and workarounds

Apply the available kernel patches that replace simple_strtoul() with kstrtouint() in the EDAC sysfs handler. Fixed versions include Linux kernel 6.12.111, 6.18.53, 7.2.7, and 7.3-rc2 (commit IDs: ea01c061, 528052af, 0e022ee4, 66cc9dec). As a workaround until patching is possible, restrict write access to /sys/devices/system/edac/*/poll_msec to trusted users only using filesystem permissions or Linux Security Modules (e.g., SELinux, AppArmor) (Github Advisory).

Community reactions

The vulnerability received routine coverage from CVE aggregation services and vulnerability databases shortly after disclosure on September 25, 2026. A Reddit post in r/pwnhub included it in a daily CVE brief. No notable researcher commentary, vendor statements beyond the kernel patch, or significant media coverage has been identified, consistent with its low severity and limited exploitability (Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Affected

sid

linux: 7.2.7-1

Fixed

trixie

linux

Affected

Ubuntu

Unknown

bionic (esm-infra)

linux

Unknown

bionic (fips-updates)

linux-fips

Unknown

bionic (fips)

linux-fips

Unknown

devel

linux

Unknown

focal (esm-infra)

linux

Unknown

focal (fips-updates)

linux-fips

Unknown

focal (fips)

linux-fips

Unknown

jammy

linux

Unknown

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

kernel-rt.src

Affected

RHEL 9

kernel.src

Affected

RHEL 10

kernel.src

Affected

Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100075CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux
NoYesSep 25, 2026
CVE-2026-98159MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesSep 25, 2026
CVE-2026-98158MEDIUM5.7
  • Linux Kernel logoLinux Kernel
  • kernel-64k-core
NoYesSep 25, 2026
CVE-2026-98161MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-modules-partner
NoYesSep 25, 2026
CVE-2026-98157MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-core
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management