Incorrect calculation in Linux kernel - CVE-2026-98324

 

Incorrect calculation in Linux kernel - CVE-2026-98324

Published: October 8, 2026


Vulnerability identifier: #VU153953
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98324
CWE-ID: CWE-682
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to incorrect hardware descriptor counting in the Linux kernel PXA DMA driver when allocating and freeing hardware descriptors. A local user can trigger descriptor processing with an incorrect count, causing out-of-bounds descriptor access or attempts to free entries that were never allocated, to compromise system confidentiality, integrity, and availability.

Automatic counter initialization by kzalloc_flex() depends on compiler support for __builtin_counted_by_ref(), available in GCC 15.1 or later and Clang 22.1 or later.


Affected software

Linux kernel

How to mitigate CVE-2026-98324

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins