CVE-2026-98298
Received Received - Intake

Memory Corruption in Linux Kernel DMA Engine

Vulnerability report for CVE-2026-98298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist putting each entry into 'sg', but the entry length is read from 'sgl' (the list head) instead of 'sg' (the current entry): for_each_sg(sgl, sg, sg_len, i) { addr = sg_dma_address(sg); avail = sg_dma_len(sgl); /* should be 'sg' */ Consequently 'avail' is always the length of the first entry. For multi-sg lists this causes out-of-bounds reads when a later entry is shorter than the first, and silent data loss when it is longer. Single-sg or uniformly-sized lists happen to mask the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux c8acd6aa6bed3c0fd7898202f4ebc534db9085f2
Linux Linux 3.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's MMP DMA engine driver. It involves a bug in the mmp_pdma_prep_slave_sg() function where the wrong scatterlist entry length is used during DMA operations. The code incorrectly reads the length from the first entry of the scatterlist instead of the current entry being processed.

Detection Guidance

This vulnerability is specific to the Linux kernel's mmp_pdma driver and requires kernel code inspection or runtime detection. There are no standard network or system commands to directly detect this issue. Reviewing kernel logs for DMA-related errors or examining the mmp_pdma driver code for the described flaw may help identify affected systems.

Impact Analysis

This bug can cause out-of-bounds memory reads if a scatterlist contains entries of varying lengths. It may also lead to silent data loss when later entries are longer than the first. Systems using affected DMA operations could experience crashes, corruption, or unexpected behavior.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If using a distribution kernel, update to the patched version. For custom kernels, patch the mmp_pdma driver by correcting the sg_dma_len() argument from sgl to sg in the mmp_pdma_prep_slave_sg() function. Disable the mmp_pdma driver if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart