---
id: CVE-2026-98242
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dma-buf: Fix silent overflow for phys vec to sgt

  In case MMIO size is bigger than 4G and peer2peer DMA goes
  through host bridge, we trigger a code path that assigns th…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dma-buf: Fix silent overflow for phys vec to sgt

  In case MMIO size is bigger than 4G and peer2peer DMA goes
  through host bridge, we trigger a code path that assigns th…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c <
    6b98fd7106d4e486f432664893dcd4d6fa3a9693
  - >-
    Linux >= 3aa31a8bb11e47c0ff2b306988d1756b810c1c3c <
    b344ca94e8cc85796f16ea25e2e5a8e0303fe813
  - Linux 6.19
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:12.253'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98242'
references:
  - url: 'https://git.kernel.org/stable/c/6b98fd7106d4e486f432664893dcd4d6fa3a9693'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b344ca94e8cc85796f16ea25e2e5a8e0303fe813'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.432Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

dma-buf: Fix silent overflow for phys vec to sgt

In case MMIO size is bigger than 4G and peer2peer DMA goes
through host bridge, we trigger a code path that assigns the
total linked IOVA (which is greater than 4G) to mapped_len.

Previously, `mapped_len` was declared as 32-bit `unsigned int`.
When accumulating `size_t` lengths, this leads to a silent wrap-around.
This truncation causes truncated lengths to be passed to functions
like `fill_sg_entry()`.

Fix this by changing `mapped_len` to `size_t` (64-bit). While
at it, fix similar potential overflow issues in `calc_sg_nents`
by using `check_add_overflow()` for `nents` and using
`unsigned int` for the loop iterator in `fill_sg_entry` to match.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
