SB2026100770 - Out-of-bounds read in Linux kernel dma driver
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-98298)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause out-of-bounds reads and silent data loss.
The vulnerability exists due to incorrect scatterlist entry length selection in mmp_pdma_prep_slave_sg() when preparing DMA transfers from scatterlists containing entries of different lengths. A local user can trigger processing of such a scatterlist to cause out-of-bounds reads and silent data loss.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47
- https://git.kernel.org/stable/c/2148db529f082d6e3ca95413bf943442f4ef30cc
- https://git.kernel.org/stable/c/4a33886057e6d127555efb022879c583e966acc5
- https://git.kernel.org/stable/c/54ccc01012a240476edf641bf1a2b8bff54fe6ae
- https://git.kernel.org/stable/c/88a505330eb06128f7ce79a4c5e4832b7601b3d1
- https://git.kernel.org/stable/c/bae65e4925928f77824ca0103122e2ed20ef5802
- https://git.kernel.org/stable/c/d920c07aa6d89ec11afdb6976aafaee9563a5234
- https://git.kernel.org/stable/c/f448a5f5bd10d792440a1b08cf2e8f311767032d