SB2026100803 - Incorrect calculation in Linux kernel dma driver



SB2026100803 - Incorrect calculation in Linux kernel dma driver

Published: October 8, 2026

Security Bulletin ID SB2026100803
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect calculation (CVE-ID: CVE-2026-98324)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to incorrect hardware descriptor counting in the Linux kernel PXA DMA driver when allocating and freeing hardware descriptors. A local user can trigger descriptor processing with an incorrect count, causing out-of-bounds descriptor access or attempts to free entries that were never allocated, to compromise system confidentiality, integrity, and availability.

Automatic counter initialization by kzalloc_flex() depends on compiler support for __builtin_counted_by_ref(), available in GCC 15.1 or later and Clang 22.1 or later.


Remediation

Install update from vendor's website.