CVE-2026-98324

high

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: pxa: fix double counting of the hw descriptors pxad_alloc_desc() was converted from kzalloc(struct_size(sw_desc, hw_desc, nb_hw_desc), GFP_NOWAIT) to kzalloc_flex(), which sets the __counted_by() counter sw_desc->nb_desc itself - but only where the compiler has __builtin_counted_by_ref(), so from gcc 15.1 or clang 22.1 on. The loop below it still increments nb_desc, which makes it come out doubled there and correct elsewhere. nb_desc is what pxad_free_desc() iterates over and what set_updater_desc() indexes from, so set it explicitly and drop the increment. The error path has to lower it to the number of descriptors allocated so far, otherwise pxad_free_desc() would free entries that were never allocated.

References

https://git.kernel.org/stable/c/f6504be006aa4bb4bd26285f410a885c17920d65

https://git.kernel.org/stable/c/1de93785f32b450e9eae1e4fcfb7d03eb49eb27e

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93309

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00129