Database/Kernel, userspace & hypervisor
Linux kernel dma-buf: 32-bit mapped_len truncates peer-to-peer DMA mappings larger than 4 GiB
Impact
When a peer-to-peer DMA transfer over a MMIO aperture larger than 4 GiB is routed through the host bridge, the total linked IOVA is accumulated into a 32-bit mapped_len, which silently wraps and passes a truncated length into fill_sg_entry(). The scatterlist that comes out does not describe the memory the caller asked to map, and calc_sg_nents() can overflow its nents count as well. This is the code path behind GPU and accelerator peer-to-peer DMA and RDMA-to-GPU transfers - exactly the large BAR mappings on datacenter accelerators - so a mismapped transfer means DMA against the wrong addresses rather than a clean failure. The record describes it as a silent overflow fixed in the stable trees; it does not characterise it as a proven privilege escalation or give a CVSS score.
Who can reach it
Local: a process that can set up a peer-to-peer DMA mapping through dma-buf against a device exposing more than 4 GiB of MMIO - on a GPU node, any tenant holding a GPU device node and using a p2p-capable framework or RDMA path. No remote reach and no authentication beyond device access.
What to do
Take the stable kernel update that widens mapped_len to size_t and adds check_add_overflow() in calc_sg_nents(), then drain and reboot each node. dma-buf is built into the kernel image on server configurations, so there is no module-reload shortcut. The record names only the two stable commits, not a fixed release version.
References
Related entries
- Linux kernel dma-fence: lost RCU protection after signalling allows use-after-free of fence name stringsCVE-2026-98243 · Linux kernel dma-buf/dma-fence (timeline and driver name accessors)Unscored
- Linux kernel arm64: LSE percpu ops on 8/16-bit types read and write 32 bits of memoryCVE-2026-98248 · Linux kernel arm64 percpu operations (LSE atomics on 8- and 16-bit types)Unscored
- Linux kernel RDMA/core: iWARP port mapper initialises its refcount after publishing the requestCVE-2026-98252 · Linux kernel RDMA/core iWARP port mapper (iwpm_get_nlmsg_request refcount init)Unscored
- Linux kernel perf: NULL pmu dereference when a PMU module unloads with an event openCVE-2026-98268 · Linux kernel perf (is_include_guest_event / mediated PMU accounting)Unscored
- Linux kernel x86/kprobes: wrong return address when probing a CS-prefixed CALL crashes the hostCVE-2026-98273 · Linux kernel x86/kprobes (int3_emulate_call instruction length)Unscored
- powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table accessCVE-2026-98282 · Linux kernel powerpc/iommu (iommu_tce_check_ioba npages validation)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.