CVE-2026-98242: dma-buf: Fix silent overflow for phys vec to sgt

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

dma-buf: Fix silent overflow for phys vec to sgt

In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mappedlen.

Previously, mappedlen was declared as 32-bit unsigned int. When accumulating sizet lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like fillsgentry().

Fix this by changing mappedlen to sizet (64-bit). While at it, fix similar potential overflow issues in calcsgnents by using checkaddoverflow() for nents and using unsigned int for the loop iterator in fillsgentry to match.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Change mapped_len from 32-bit unsigned int to size_t (64-bit); use an unsigned int loop iterator in fill_sg_entry to match; and use check_add_overflow() for nents in calc_sg_nents to prevent silent length and entry-count overflow.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203