PT-2026-106653 · Linux · Linux

CVE-2026-98324

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: pxa: fix double counting of the hw descriptors
pxad alloc desc() was converted from
kzalloc(struct size(sw desc, hw desc, nb hw desc), GFP NOWAIT)
to kzalloc flex(), which sets the counted by() counter sw desc->nb desc itself - but only where the compiler has builtin counted by ref(), so from gcc 15.1 or clang 22.1 on. The loop below it still increments nb desc, which makes it come out doubled there and correct elsewhere.
nb desc is what pxad free desc() iterates over and what set updater desc() indexes from, so set it explicitly and drop the increment. The error path has to lower it to the number of descriptors allocated so far, otherwise pxad free desc() would free entries that were never allocated.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98324

Produtos afetados

Linux