{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98324","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.340Z","datePublished":"2026-10-06T08:46:17.919Z","dateUpdated":"2026-10-07T06:50:04.172Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:04.172Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: pxa: fix double counting of the hw descriptors\n\npxad_alloc_desc() was converted from\n\n        kzalloc(struct_size(sw_desc, hw_desc, nb_hw_desc), GFP_NOWAIT)\n\nto kzalloc_flex(), which sets the __counted_by() counter sw_desc->nb_desc\nitself - but only where the compiler has __builtin_counted_by_ref(), so\nfrom gcc 15.1 or clang 22.1 on. The loop below it still increments\nnb_desc, which makes it come out doubled there and correct elsewhere.\n\nnb_desc is what pxad_free_desc() iterates over and what\nset_updater_desc() indexes from, so set it explicitly and drop the\nincrement. The error path has to lower it to the number of descriptors\nallocated so far, otherwise pxad_free_desc() would free entries that were\nnever allocated."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The fault is in pxad_alloc_desc()/set_updater_desc() in drivers/dma/pxa_dma.c and is triggered by any local I/O that makes a PXA DMA client prep a transfer, e.g. read() on SD/MMC storage via pxamci -> dmaengine_prep_slave_sg() -> pxad_prep_slave_sg(). No remote protocol supplies the bad state.\nAC:L - On builds with gcc>=15.1 or clang>=22.1 (the current default toolchains), kzalloc_flex() already sets nb_desc=N and the loop's nb_desc++ makes it 2N on every allocation, so every DMA prep overruns hw_desc[]. Controlling the out-of-bounds slot only needs ordinary slab grooming of the neighbouring kmalloc object.\nPR:L - An unprivileged local user can start the vulnerable path just by reading a file on PXA MMC-backed storage (or using SPI/audio devices that use pxa_dma). No capability check sits between the read and pxad_prep_slave_sg().\nUI:N - The attacker drives the I/O that leads to pxad_alloc_desc() and set_updater_desc() through their own syscalls. No victim action is needed.\nS:U - Corruption stays within kernel slab and dma_pool memory under the same kernel authority, with no VM or IOMMU boundary crossed.\nC:H - set_updater_desc(), is_desc_completed() and pxad_residue() read pointers from hw_desc[2N-1] and hw_desc[2N-2], past the kzalloc_flex allocation into adjacent slab memory, and dereference them. A groomed neighbouring object gives a pointer-controlled read.\nI:H - set_updater_desc() writes ddadr/dsadr/dtadr/dcmd (16 bytes) through the out-of-bounds pointer hw_desc[nb_desc-1], and pxad_free_desc() calls dma_pool_free() on up to N out-of-bounds pointers. With a groomed neighbour this is a controlled-address write plus an invalid free.\nA:H - Every pxa_dma transfer dereferences pointers past the allocation and frees nonexistent dma_pool entries in pxad_free_desc(), causing an oops or pool corruption on the first MMC/SPI DMA."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/pxa_dma.c"],"versions":[{"version":"69050f8d6d075dc01af7a5f2f550a8067510366f","lessThan":"1de93785f32b450e9eae1e4fcfb7d03eb49eb27e","status":"affected","versionType":"git"},{"version":"69050f8d6d075dc01af7a5f2f550a8067510366f","lessThan":"f6504be006aa4bb4bd26285f410a885c17920d65","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/pxa_dma.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1de93785f32b450e9eae1e4fcfb7d03eb49eb27e"},{"url":"https://git.kernel.org/stable/c/f6504be006aa4bb4bd26285f410a885c17920d65"}],"title":"dmaengine: pxa: fix double counting of the hw descriptors","x_generator":{"engine":"bippy-1.2.0"}}}}