CVE-2026-98242 PUBLISHED

dma-buf: Fix silent overflow for phys vec to sgt

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

dma-buf: Fix silent overflow for phys vec to sgt

In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len.

Previously, mapped_len was declared as 32-bit unsigned int. When accumulating size_t lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like fill_sg_entry().

Fix this by changing mapped_len to size_t (64-bit). While at it, fix similar potential overflow issues in calc_sg_nents by using check_add_overflow() for nents and using unsigned int for the loop iterator in fill_sg_entry to match.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c to 6b98fd7106d4e486f432664893dcd4d6fa3a9693 (excl.)
  • affected from 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c to b344ca94e8cc85796f16ea25e2e5a8e0303fe813 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References