PT-2026-106653 · Linux · Linux

CVE-2026-98324

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: pxa: fix double counting of the hw descriptors
pxad alloc desc() was converted from
kzalloc(struct size(sw desc, hw desc, nb hw desc), GFP NOWAIT)
to kzalloc flex(), which sets the counted by() counter sw desc->nb desc itself - but only where the compiler has builtin counted by ref(), so from gcc 15.1 or clang 22.1 on. The loop below it still increments nb desc, which makes it come out doubled there and correct elsewhere.
nb desc is what pxad free desc() iterates over and what set updater desc() indexes from, so set it explicitly and drop the increment. The error path has to lower it to the number of descriptors allocated so far, otherwise pxad free desc() would free entries that were never allocated.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98324

Affected Products

Linux