{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97506","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T16:01:01.151Z","datePublished":"2026-09-24T16:04:55.504Z","dateUpdated":"2026-10-03T10:59:03.858Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:59:03.858Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ixp4xx - fix buffer chain unwind on allocation failure\n\nchainup_buffers() builds a linked list of buffer descriptors for a\nscatterlist. If dma_pool_alloc() fails while constructing the list, the\ncurrent code sets buf to NULL and later dereferences it unconditionally\nat the end of the function:\n\n  buf->next = NULL;\n  buf->phys_next = 0;\n\nThis can lead to a null-pointer dereference on allocation failure.\n\nIf the failure happens after part of the descriptor chain has already\nbeen allocated and DMA-mapped, the partially constructed chain also\nneeds to be released.\n\nFix this by terminating the partially constructed chain on allocation\nfailure and letting the callers unwind it via their existing cleanup\npaths. Also fix ablk_perform() to preserve the hook pointers before\nchecking for failure, so partially built chains can be freed correctly."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/intel/ixp4xx/ixp4xx_crypto.c"],"versions":[{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"d4007867be42d71795b78fa7f8ce7514dda9ca83","status":"affected","versionType":"git"},{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"4918b0bd7d2baafb45d87dca9e322137c96005c2","status":"affected","versionType":"git"},{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"8c37bc8d6a6f77bf9593fb1bcab6c14c7cf02991","status":"affected","versionType":"git"},{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"04cb00106ca4d0fa9eca24cadc4eda6036e855c8","status":"affected","versionType":"git"},{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"028a7f4f3d69e551f6bf9f728d547bbf4cfc707d","status":"affected","versionType":"git"},{"version":"0d44dc59b2b434b29aafeae581d06f81efac7c83","lessThan":"25056329384010a8672552b134f609601dc4f80e","status":"affected","versionType":"git"},{"version":"5a80273150a8a1725fa70418d106eb1f2ee8fd2f","status":"affected","versionType":"git"},{"version":"82a8becb9c2c52fc5e67057a43aeded1f0731e7b","status":"affected","versionType":"git"},{"version":"68845515c8b11791b547a2838e22c27dfa3115ee","status":"affected","versionType":"git"},{"version":"2.6.27.22","lessThan":"2.6.28","status":"affected","versionType":"semver"},{"version":"2.6.28.10","lessThan":"2.6.29","status":"affected","versionType":"semver"},{"version":"2.6.29.3","lessThan":"2.6.30","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/intel/ixp4xx/ixp4xx_crypto.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27.22"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d4007867be42d71795b78fa7f8ce7514dda9ca83"},{"url":"https://git.kernel.org/stable/c/4918b0bd7d2baafb45d87dca9e322137c96005c2"},{"url":"https://git.kernel.org/stable/c/8c37bc8d6a6f77bf9593fb1bcab6c14c7cf02991"},{"url":"https://git.kernel.org/stable/c/04cb00106ca4d0fa9eca24cadc4eda6036e855c8"},{"url":"https://git.kernel.org/stable/c/028a7f4f3d69e551f6bf9f728d547bbf4cfc707d"},{"url":"https://git.kernel.org/stable/c/25056329384010a8672552b134f609601dc4f80e"}],"title":"crypto: ixp4xx - fix buffer chain unwind on allocation failure","x_generator":{"engine":"bippy-1.2.0"}}}}