CVE-2026-74380
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix iommu_map_sgtable() return value check
Commit "iommu: return full error code from iommu_map_sg_atomic" changed iommu_map_sgtable() to return an ssize_t and negative values in error cases, rather than a size_t and a zero.
pin_job() also was incorrectly assigning to 'int', which could cause overflows into negative values.
Update pin_job() to correctly check for errors from iommu_map_sgtable.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < 5f3985c2a500df3126cb12a2e0ccf26a40bc495d | affected |
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < 3ac173e46ef6fda9c9df8d47cdff4df962df9728 | affected |
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < 2a68928c445138961e2c451983b473aeb3f5b999 | affected |
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < 79240eee5a40014d9edfabe19f06b35ffa84e5f8 | affected |
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < e024c7993d839503d6c1f0044b8fc537c30300e9 | affected |
| Linux | Linux | ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b < 18f74762013a4b6aa6f905c4459e0f506f9c5c7b | affected |
| Linux | Linux | 5.15 | affected |
| Linux | Linux | 0 < 5.15 | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.97 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/5f3985c2a500df3126cb12a2e0ccf26a40bc495d
- https://git.kernel.org/stable/c/3ac173e46ef6fda9c9df8d47cdff4df962df9728
- https://git.kernel.org/stable/c/2a68928c445138961e2c451983b473aeb3f5b999
- https://git.kernel.org/stable/c/79240eee5a40014d9edfabe19f06b35ffa84e5f8
- https://git.kernel.org/stable/c/e024c7993d839503d6c1f0044b8fc537c30300e9
- https://git.kernel.org/stable/c/18f74762013a4b6aa6f905c4459e0f506f9c5c7b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.