
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98157 is an input validation flaw in the Linux kernel's EDAC (Error Detection and Correction) subsystem that can lead to a local denial of service. The vulnerability exists in the EDAC/device_sysfs component, where the poll_msec sysfs interface uses simple_strtoul() — which accepts unsigned long values — but stores the result in an unsigned int field, causing silent truncation on 64-bit systems for values exceeding UINT_MAX. Additionally, the absence of a lower-bound check allows a value of 0 to be written, causing the poll work queue to spin without delay and consume 100% CPU. The vulnerability affects Linux kernel versions from 2.6.23 through multiple stable branches, with fixes available in versions 6.12.111, 6.18.53, 7.2.7, and 7.3-rc2. It was disclosed on September 25, 2026, and carries an estimated CVSS severity of Medium with an EPSS score of 0.0 (Github Advisory, Feedly).
The root cause is improper input validation (related to CWE-20) in the poll_msec sysfs store handler within EDAC/device_sysfs. The handler calls simple_strtoul(), which parses values as unsigned long; on 64-bit Linux systems, unsigned long is 64 bits while unsigned int is 32 bits, so values greater than UINT_MAX (4,294,967,295) are silently truncated when assigned to the poll_msec field, resulting in unexpected polling intervals. A second issue is the lack of a minimum value check: writing 0 to the sysfs file causes the EDAC poll work to reschedule itself with zero delay, creating a tight busy-loop that saturates a CPU core. Exploitation requires local access and write permissions to /sys/devices/system/edac/*/poll_msec. The fix replaces simple_strtoul() with kstrtouint(), which rejects out-of-range values at parse time, and adds a value < 1 guard (Github Advisory).
The primary impact is a local denial of service: a user with write access to the EDAC sysfs interface can cause a CPU core to spin at 100% utilization indefinitely by writing a zero value to poll_msec, degrading system performance and potentially affecting availability of services running on the host. On 64-bit systems, writing values larger than UINT_MAX results in silent truncation, leading to unpredictable EDAC polling behavior that could mask hardware memory errors. There is no evidence of confidentiality or integrity impact beyond the availability disruption (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is locally exploitable only, requiring write access to the EDAC sysfs file, which limits the attack surface to privileged or specially configured local users. The EPSS score is 0.0, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Github Advisory, Feedly).
ls -la /sys/devices/system/edac/*/poll_msec.echo 0 > /sys/devices/system/edac/<device>/poll_msec. This causes the EDAC poll work queue to spin continuously, consuming 100% of a CPU core.echo 4294967296 > /sys/devices/system/edac/<device>/poll_msec) to cause silent truncation, resulting in an unexpected polling interval (e.g., 0 or 1 ms) that may mask hardware memory error detection (Github Advisory)./sys/devices/system/edac/*/poll_msec with values of 0 or values exceeding 4294967295.top or perf), particularly a work queue thread associated with EDAC polling.dmesg) showing abnormal EDAC polling behavior or repeated EDAC work queue scheduling at unusually high frequency.Apply the available kernel patches that replace simple_strtoul() with kstrtouint() in the EDAC sysfs handler. Fixed versions include Linux kernel 6.12.111, 6.18.53, 7.2.7, and 7.3-rc2 (commit IDs: ea01c061, 528052af, 0e022ee4, 66cc9dec). As a workaround until patching is possible, restrict write access to /sys/devices/system/edac/*/poll_msec to trusted users only using filesystem permissions or Linux Security Modules (e.g., SELinux, AppArmor) (Github Advisory).
The vulnerability received routine coverage from CVE aggregation services and vulnerability databases shortly after disclosure on September 25, 2026. A Reddit post in r/pwnhub included it in a daily CVE brief. No notable researcher commentary, vendor statements beyond the kernel patch, or significant media coverage has been identified, consistent with its low severity and limited exploitability (Feedly).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
focal (fips)
linux-fips
jammy
linux
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."