GHSA-v74x-xvfc-h3j3HighCVSS 8.8

In the Linux kernel, the following vulnerability has been resolved: iommu/dma-iommu: Fix wrong...

Published
August 15, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path

In iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length of the current scatterlist segment s is incorrectly assigned from the head entry sg->length instead of the current entry s->length.

This typo causes all P2PDMA segments in the scatterlist to inherit the length of the first segment, leading to corrupted DMA lengths for multi- segment scatterlists.

Fix this by using s->length instead of sg->length.

🔗 References (4)