CVE-2026-98324: dmaengine: pxa: fix double counting of the hw descriptors
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: pxa: fix double counting of the hw descriptors
pxadallocdesc() was converted from
kzalloc(structsize(swdesc, hwdesc, nbhwdesc), GFPNOWAIT)
to kzallocflex(), which sets the countedby() counter swdesc->nbdesc itself - but only where the compiler has builtincountedbyref(), so from gcc 15.1 or clang 22.1 on. The loop below it still increments nbdesc, which makes it come out doubled there and correct elsewhere.
nbdesc is what pxadfreedesc() iterates over and what setupdaterdesc() indexes from, so set it explicitly and drop the increment. The error path has to lower it to the number of descriptors allocated so far, otherwise pxadfreedesc() would free entries that were never allocated.