CVE-2026-98242
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: Fix silent overflow for phys vec to sgt
In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len.
Previously, mapped_len was declared as 32-bit unsigned int.
When accumulating size_t lengths, this leads to a silent wrap-around.
This truncation causes truncated lengths to be passed to functions
like fill_sg_entry().
Fix this by changing mapped_len to size_t (64-bit). While
at it, fix similar potential overflow issues in calc_sg_nents
by using check_add_overflow() for nents and using
unsigned int for the loop iterator in fill_sg_entry to match.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c < 6b98fd7106d4e486f432664893dcd4d6fa3a9693 | affected |
| Linux | Linux | 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c < b344ca94e8cc85796f16ea25e2e5a8e0303fe813 | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/6b98fd7106d4e486f432664893dcd4d6fa3a9693
- https://git.kernel.org/stable/c/b344ca94e8cc85796f16ea25e2e5a8e0303fe813
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.