dma-buf: Fix silent overflow for phys vec to sgt
Summary
| CVE | CVE-2026-98242 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:12 UTC |
| Updated | 2026-10-06 09:18:12 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
dma-buf: Fix silent overflow for phys vec to sgt
In case MMIO size is bigger than 4G and peer2peer DMA goes
through host bridge, we trigger a code path that assigns the
total linked IOVA (which is greater than 4G) to mapped_len.
Previously, `mapped_len` was declared as 32-bit `unsigned int`.
When accumulating `size_t` lengths, this leads to a silent wrap-around.
This truncation causes truncated lengths to be passed to functions
like `fill_sg_entry()`.
Fix this by changing `mapped_len` to `size_t` (64-bit). While
at it, fix similar potential overflow issues in `calc_sg_nents`
by using `check_add_overflow()` for `nents` and using
`unsigned int` for the loop iterator in `fill_sg_entry` to match. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c 6b98fd7106d4e486f432664893dcd4d6fa3a9693 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c b344ca94e8cc85796f16ea25e2e5a8e0303fe813 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.19 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.19 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.8 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/b344ca94e8cc85796f16ea25e2e5a8e0303fe813 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6b98fd7106d4e486f432664893dcd4d6fa3a9693 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.