PT-2026-106653 · Linux · Linux
CVE-2026-98324
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: pxa: fix double counting of the hw descriptors
pxad alloc desc() was converted from
kzalloc(struct size(sw desc, hw desc, nb hw desc), GFP NOWAIT)to kzalloc flex(), which sets the counted by() counter sw desc->nb desc
itself - but only where the compiler has builtin counted by ref(), so
from gcc 15.1 or clang 22.1 on. The loop below it still increments
nb desc, which makes it come out doubled there and correct elsewhere.
nb desc is what pxad free desc() iterates over and what
set updater desc() indexes from, so set it explicitly and drop the
increment. The error path has to lower it to the number of descriptors
allocated so far, otherwise pxad free desc() would free entries that were
never allocated.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux