CVE-2026-98242
Description
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: Fix silent overflow for phys vec to sgt
In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len.
Previously, mapped_len was declared as 32-bit unsigned int. When accumulating size_t lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like fill_sg_entry().
Fix this by changing mapped_len to size_t (64-bit). While at it, fix similar potential overflow issues in calc_sg_nents by using check_add_overflow() for nents and using unsigned int for the loop iterator in fill_sg_entry to match.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.