CVE-2026-98242

Source
https://cve.org/CVERecord?id=CVE-2026-98242
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98242.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98242
Downstream
Published
2026-10-06T08:45:12Z
Modified
2026-10-08T02:52:54Z
Summary
dma-buf: Fix silent overflow for phys vec to sgt
Details

In the Linux kernel, the following vulnerability has been resolved:

dma-buf: Fix silent overflow for phys vec to sgt

In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len.

Previously, mapped_len was declared as 32-bit unsigned int. When accumulating size_t lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like fill_sg_entry().

Fix this by changing mapped_len to size_t (64-bit). While at it, fix similar potential overflow issues in calc_sg_nents by using check_add_overflow() for nents and using unsigned int for the loop iterator in fill_sg_entry to match.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98242.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3aa31a8bb11e47c0ff2b306988d1756b810c1c3c
Fixed
6b98fd7106d4e486f432664893dcd4d6fa3a9693
Fixed
b344ca94e8cc85796f16ea25e2e5a8e0303fe813

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98242.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98242.json"