Sceawere

Vulnerability Detail

CVE-2026-98324UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel DMA Descriptor Miscount

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: pxa: fix double counting of the hw descriptors pxad_alloc_desc() was converted from kzalloc(struct_size(sw_desc, hw_desc, nb_hw_desc), GFP_NOWAIT) to kzalloc_flex(), which sets the __counted_by() counter sw_desc->nb_desc itself - but only where the compiler has __builtin_counted_by_ref(), so from gcc 15.1 or clang 22.1 on. The loop below it still increments nb_desc, which makes it come out doubled there and correct elsewhere. nb_desc is what pxad_free_desc() iterates over and what set_updater_desc() indexes from, so set it explicitly and drop the increment. The error path has to lower it to the number of descriptors allocated so far, otherwise pxad_free_desc() would free entries that were never allocated.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-06T09:18:24.573Z",
  "pubdate": "2026-10-06T09:18:24.573Z",
  "executiveSummary": "A memory management vulnerability exists in the Linux kernel's pxa dmaengine driver, specifically within the descriptor allocation logic.\nThe issue stems from an improper implementation of kzalloc_flex(), which resulted in the double-counting of hardware descriptors stored within the sw_desc structure.\nThis vulnerability leads to integer inaccuracies regarding the number of allocated descriptors (nb_desc), directly impacting functions responsible for memory cleanup (pxad_free_desc) and hardware descriptor indexing (set_updater_desc).\nAn attacker capable of triggering DMA engine operations might exploit this miscount to cause memory corruption, specifically heap-based buffer overflows or invalid memory access during the freeing process.\nThe vulnerability affects systems utilizing the pxa dmaengine driver, particularly those compiled with modern toolchains (GCC 15.1+ or Clang 22.1+) that support __builtin_counted_by_ref().\nFailure to remediate allows for potential kernel panic scenarios or memory corruption, posing a significant risk to system stability and security integrity.",
  "technicalDetails": "The root cause is a logic error in pxad_alloc_desc() introduced during the refactoring of memory allocation from kzalloc() to kzalloc_flex(). The transition to kzalloc_flex() automatically sets the __counted_by() attribute for the sw_desc->nb_desc member when using compatible compilers (GCC 15.1+, Clang 22.1+).\nThe existing source code contained a subsequent loop that manually incremented sw_desc->nb_desc. This resulted in the descriptor count being effectively doubled for the internal counter, while the actual allocated memory remained sized for the intended count.\nThe sw_desc->nb_desc variable is critical for downstream logic. Specifically, pxad_free_desc() utilizes this counter to iterate through and kfree() descriptor entries. When the count is inflated, pxad_free_desc() attempts to free unallocated memory or invalid heap addresses. Similarly, set_updater_desc() uses this count to index descriptors, leading to out-of-bounds access within the hw_desc array if the index exceeds the true allocation size.\nThe exploitation flow involves a kernel-level memory management flaw where the discrepancy between the reported count and the actual allocated structure size triggers a heap corruption. During the error path in pxad_alloc_desc(), failure to correctly adjust nb_desc leads to a scenario where subsequent calls to pxad_free_desc() act upon uninitialized or out-of-bounds pointer arrays.\nThis vulnerability does not require complex remote network access; it is an internal kernel-level memory safety issue. The threat model includes local users or processes with sufficient privileges to interact with the dmaengine character device or trigger DMA descriptor allocation. An exploit could lead to a Denial of Service (DoS) via kernel panic or, in more severe cases, an attacker could manipulate the heap layout to achieve arbitrary code execution by leveraging the use-after-free or out-of-bounds write conditions provided by the incorrect descriptor count."
}
CVE-2026-98324: Linux Kernel DMA Descriptor Miscount (HIGH Severity, CVSS: 7.8) | Sceawere