CVE-2026-98298

Source
https://cve.org/CVERecord?id=CVE-2026-98298
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98298.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98298
Downstream
Published
2026-10-06T08:45:56Z
Modified
2026-10-08T02:52:56Z
Summary
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()

In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist putting each entry into 'sg', but the entry length is read from 'sgl' (the list head) instead of 'sg' (the current entry):

for_each_sg(sgl, sg, sg_len, i) {
    addr = sg_dma_address(sg);
    avail = sg_dma_len(sgl);   /* should be 'sg' */

Consequently 'avail' is always the length of the first entry. For multi-sg lists this causes out-of-bounds reads when a later entry is shorter than the first, and silent data loss when it is longer. Single-sg or uniformly-sized lists happen to mask the issue.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98298.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Fixed
f448a5f5bd10d792440a1b08cf2e8f311767032d
Fixed
2148db529f082d6e3ca95413bf943442f4ef30cc
Fixed
d920c07aa6d89ec11afdb6976aafaee9563a5234
Fixed
4a33886057e6d127555efb022879c583e966acc5
Fixed
88a505330eb06128f7ce79a4c5e4832b7601b3d1
Fixed
bae65e4925928f77824ca0103122e2ed20ef5802
Fixed
54ccc01012a240476edf641bf1a2b8bff54fe6ae
Fixed
075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98298.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98298.json"