
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98259 is a Linux kernel vulnerability in the DAX (Direct Access) filesystem subsystem (fs/dax) that causes a kernel panic when dax_to_folio() is called with an empty or zero xarray entry. The flaw affects Linux kernel version 6.15 and was introduced at commit 38607c62b34b. It was published on October 6, 2026, with fixes available in kernel versions 6.18.54+ and 7.2.8+. The estimated CVSS severity is Medium (Feedly, VulDB).
The root cause is a missing input validation check (CWE-476, NULL/invalid pointer dereference) in the DAX filesystem layer. Specifically, dax_to_folio() is called in dax_associate_entry(), dax_disassociate_entry(), and dax_busy_page() before verifying whether the xarray entry is empty or a zero page entry, leading to an invalid kernel memory access at a virtual address such as fffffdffbf000008. A prior commit (98c183a4fccf, "fs/dax: don't disassociate zero page entries") added guards in the associate/disassociate paths, but those guards were placed after the problematic dax_to_folio() call, and dax_busy_page() remained unguarded. The fix moves the empty-entry check to occur before dax_to_folio() is invoked in all three affected functions (Feedly).
Successful triggering of this vulnerability results in a kernel panic (system crash), causing a complete loss of availability for the affected system. The issue manifests during boot of a virtual machine with DAX-enabled storage (e.g., persistent memory devices like pmem), making affected systems potentially unbootable or unstable. There is no evidence of confidentiality or integrity impact; the primary consequence is a denial of service at the kernel level (Feedly).
There are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and no threat actor attribution associated with CVE-2026-98259. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to boot or operate a system with DAX-enabled storage configured, which limits the practical attack surface primarily to local or privileged contexts such as VM administrators (Feedly).
The Linux kernel project has released fixes for this vulnerability. Patched versions include kernel 6.18.54 (and later 6.18.x releases) and 7.2.8 (and later 7.2.x releases), as well as the 7.3-rc4 release candidate. The specific fix commits are 44ab7420ab52ab6c04bf225cac7c5c007cedd6c7, 185cd2f5fe1e3319853cf065905b2885ad0bcbf8, and 8e2b8614039853e68d5338e37821e8bcee9fc05f. Users running kernel 6.15 with DAX-enabled storage should upgrade to a patched kernel version as soon as possible; as a temporary workaround, disabling DAX on storage devices can prevent the panic from occurring (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."