{"id":"CVE-2026-98242","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: Fix silent overflow for phys vec to sgt\n\nIn case MMIO size is bigger than 4G and peer2peer DMA goes\nthrough host bridge, we trigger a code path that assigns th…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: Fix silent overflow for phys vec to sgt\n\nIn case MMIO size is bigger than 4G and peer2peer DMA goes\nthrough host bridge, we trigger a code path that assigns th…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c < 6b98fd7106d4e486f432664893dcd4d6fa3a9693","Linux >= 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c < b344ca94e8cc85796f16ea25e2e5a8e0303fe813","Linux 6.19"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:12.253","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98242","references":[{"url":"https://git.kernel.org/stable/c/6b98fd7106d4e486f432664893dcd4d6fa3a9693","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b344ca94e8cc85796f16ea25e2e5a8e0303fe813","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.432Z","slug":"CVE-2026-98242","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: Fix silent overflow for phys vec to sgt\n\nIn case MMIO size is bigger than 4G and peer2peer DMA goes\nthrough host bridge, we trigger a code path that assigns the\ntotal linked IOVA (which is greater than 4G) to mapped_len.\n\nPreviously, `mapped_len` was declared as 32-bit `unsigned int`.\nWhen accumulating `size_t` lengths, this leads to a silent wrap-around.\nThis truncation causes truncated lengths to be passed to functions\nlike `fill_sg_entry()`.\n\nFix this by changing `mapped_len` to `size_t` (64-bit). While\nat it, fix similar potential overflow issues in `calc_sg_nents`\nby using `check_add_overflow()` for `nents` and using\n`unsigned int` for the loop iterator in `fill_sg_entry` to match.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}