SB2026100803 - Incorrect calculation in Linux kernel dma driver
Published: October 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-98324)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.
The vulnerability exists due to incorrect hardware descriptor counting in the Linux kernel PXA DMA driver when allocating and freeing hardware descriptors. A local user can trigger descriptor processing with an incorrect count, causing out-of-bounds descriptor access or attempts to free entries that were never allocated, to compromise system confidentiality, integrity, and availability.
Automatic counter initialization by kzalloc_flex() depends on compiler support for __builtin_counted_by_ref(), available in GCC 15.1 or later and Clang 22.1 or later.
Remediation
Install update from vendor's website.