CVE-2026-98298
In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist putting each entry into 'sg', but the entry length is read from 'sgl' (the list head) instead of 'sg' (the current entry): for_each_sg(sgl, sg, sg_len, i) { addr = sg_dma_address(sg); avail = sg_dma_len(sgl); /* should be 'sg' */ Consequently 'avail' is always the length of the first entry. For multi-sg lists this causes out-of-bounds reads when a later entry is shorter than the first, and silent data loss when it is longer. Single-sg or uniformly-sized lists happen to mask the issue.
Affected versions
Linux kernel versions
3.7
and later are affected. Fixed in
5.10.271,
5.15.222,
6.1.189,
6.6.158,
6.12.112,
6.18.54,
7.2.8,
7.3-rc4
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-98298?
CVE-2026-98298 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 3.7 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-98298 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98298?
Yes. CVE-2026-98298 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 3.7 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98298 actively exploited?
No. CVE-2026-98298 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.