Incorrect calculation in Linux kernel - CVE-2026-98324
Published: October 8, 2026
Vulnerability details
The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.
The vulnerability exists due to incorrect hardware descriptor counting in the Linux kernel PXA DMA driver when allocating and freeing hardware descriptors. A local user can trigger descriptor processing with an incorrect count, causing out-of-bounds descriptor access or attempts to free entries that were never allocated, to compromise system confidentiality, integrity, and availability.
Automatic counter initialization by kzalloc_flex() depends on compiler support for __builtin_counted_by_ref(), available in GCC 15.1 or later and Clang 22.1 or later.