{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98254","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.331Z","datePublished":"2026-10-06T08:45:20.736Z","dateUpdated":"2026-10-07T06:49:42.178Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:42.178Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nswiotlb: use the adjusted address for the highmem page lookup\n\nswiotlb_bounce() reads the page frame number from the slot's recorded\norig_addr, then advances orig_addr by tlb_offset to reach the address\nthe caller asked about. The highmem branch mixes the two: the offset\nwithin the page comes from the adjusted address, the page from the value\nbefore it.\n\nOnce the adjustment crosses a page boundary the pair no longer describes\none location, and the whole copy lands one page below the intended one\nfor a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE\nwrites the device data over the wrong page and leaves the intended one\nstale, DMA_TO_DEVICE feeds the device from a page the mapping may not\ncover. Partial syncs through dma_sync_single_range_for_*() are what make\ntlb_offset non-zero.\n\nThe branch test is picked the same way, so a slot recorded in lowmem can\nbe adjusted into highmem and the lowmem path then hands a highmem\naddress to phys_to_virt().\n\nTake both from orig_addr once it is final and keep pfn in the branch\nthat uses it. PhysHighMem() asks the question straight from the address,\nas dma-debug already does."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The defect is in swiotlb_bounce(), reached only via __swiotlb_sync_single_for_cpu/_for_device from a driver's dma_sync_single_range_for_*() on a bounced buffer. No protocol message carries malformed input, and a local user can only cause it by doing I/O on a highmem buffer through such a driver.\nAC:L - Not used; the AC line below is the real value.\nPR:L - The attacker needs an ordinary local account to issue I/O whose buffers (user or page-cache pages, which can be highmem) go through an affected device's streaming DMA mapping. No capability check on the swiotlb sync path stands in the way.\nUI:N - Once the attacker's own I/O drives the partial-sync pattern, no victim action is needed. The bounce runs inside the driver's sync call.\nS:U - The bad copy is done by the kernel's own swiotlb code into kernel-managed physical memory. No IOMMU, VM or other boundary is crossed beyond the kernel's own authority.\nC:H - On DMA_TO_DEVICE, memcpy_from_page() uses pfn_to_page(PFN_DOWN(old orig_addr)) and feeds the device a whole neighbouring physical page the mapping does not cover. This can expose unrelated kernel or user data to the device.\nI:H - On DMA_FROM_DEVICE, memcpy_to_page() writes device data over the page next to the intended one, corrupting arbitrary neighbouring memory. Separately, a lowmem slot shifted into highmem sends a highmem address to phys_to_virt() and memcpy() through a bogus pointer.\nA:H - Overwriting an unrelated physical page, or calling memcpy() on a bogus phys_to_virt() pointer for a highmem address, can corrupt kernel state or fault and oops the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/dma/swiotlb.c"],"versions":[{"version":"5f89468e2f060031cd89fd4287298e0eaf246bf6","lessThan":"6e53b4d6afbde626255805d438cabb1cac482445","status":"affected","versionType":"git"},{"version":"5f89468e2f060031cd89fd4287298e0eaf246bf6","lessThan":"aa4709813b29db89f2307f968db5d24925dcdeb1","status":"affected","versionType":"git"},{"version":"5f89468e2f060031cd89fd4287298e0eaf246bf6","lessThan":"0219b72f5c209732b2f03a8cc0d7240b5e428a99","status":"affected","versionType":"git"},{"version":"5f89468e2f060031cd89fd4287298e0eaf246bf6","lessThan":"b7d7914a9ae3097e63d113007e4fb44d33d515b1","status":"affected","versionType":"git"},{"version":"e6108147dd91b94d1979b110f265710c254c99d5","status":"affected","versionType":"git"},{"version":"e77b796eb9b7ca3c1c0d574d0c155f55b59ca8d5","status":"affected","versionType":"git"},{"version":"5.10.47","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.12.14","lessThan":"5.13","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/dma/swiotlb.c"],"versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.14"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6e53b4d6afbde626255805d438cabb1cac482445"},{"url":"https://git.kernel.org/stable/c/aa4709813b29db89f2307f968db5d24925dcdeb1"},{"url":"https://git.kernel.org/stable/c/0219b72f5c209732b2f03a8cc0d7240b5e428a99"},{"url":"https://git.kernel.org/stable/c/b7d7914a9ae3097e63d113007e4fb44d33d515b1"}],"title":"swiotlb: use the adjusted address for the highmem page lookup","x_generator":{"engine":"bippy-1.2.0"}}}}