CVE-2026-98242: dma-buf: Fix silent overflow for phys vec to sgt
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: Fix silent overflow for phys vec to sgt
In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mappedlen.
Previously, mappedlen was declared as 32-bit unsigned int. When accumulating sizet lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like fillsgentry().
Fix this by changing mappedlen to sizet (64-bit). While at it, fix similar potential overflow issues in calcsgnents by using checkaddoverflow() for nents and using unsigned int for the loop iterator in fillsgentry to match.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Change mapped_len from 32-bit unsigned int to size_t (64-bit); use an unsigned int loop iterator in fill_sg_entry to match; and use check_add_overflow() for nents in calc_sg_nents to prevent silent length and entry-count overflow.