CVE-2026-98262

In the Linux kernel, the following vulnerability has been resolved: ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board. The failure is seen as soon as the ahci driver is probed, and booting with iommu=off does not solve the problem. Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0' for HBAs that do not support 64-bit addressing. For HBAs that do support 64-bit addressing, the registers are read write, with a reset value that is Implementation Specific. When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64. Thus, in this case, we need to explicitly clear the registers to 0.

Package Linux Kernel
Published 2026-10-06
Last modified 2026-10-06
Patch available
Yes

Affected versions

Linux kernel versions 2.6.22 and later are affected. Fixed in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, 7.3-rc4 and their respective stable series.

Affected from
≥ 2.6.22
Fixed in
✓ 5.10.271 5.10.x ✓ 5.15.222 5.15.x ✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.112 6.12.x ✓ 6.18.54 6.18.x ✓ 7.2.8 7.2.x ✓ 7.3-rc4

Frequently asked questions

  • What is CVE-2026-98262?

    CVE-2026-98262 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.22 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-98262 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98262?

    Yes. CVE-2026-98262 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 2.6.22 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98262 actively exploited?

    No. CVE-2026-98262 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.