Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path

In iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length
of the current scatterlist segment `s` is incorrectly assigned from the
head entry `sg->length` instead of the current entry `s->length`.

This typo causes all P2PDMA segments in the scatterlist to inherit the
length of the first segment, leading to corrupted DMA lengths for multi-
segment scatterlists.

Fix this by using `s->length` instead of `sg->length`.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kernel function iommu_dma_map_sg() incorrectly assigns the DMA length for all scatterlist segments in a PCI Programmed‑Peripheral‑to‑Peripheral DMA (P2PDMA) transfer. Instead of using the length of the current segment, the code copies the length from the first segment. This typo causes every segment in a multi‑segment scatterlist to report the same DMA length, potentially leading to truncated or overlapped DMA transfers. The resulting malformed DMA mappings can corrupt kernel memory during data movement, which may expose confidential data, trigger kernel crashes, or create a foothold for escalation of privileges.

Affected Systems

The issue affects the Linux kernel in any build that contains the legacy iommu_dma_map_sg() implementation for P2PDMA, regardless of distribution. No specific kernel versions were listed, but the vulnerability exists until the corresponding commit that corrects the length assignment is applied. Consequently, all unpatched Linux kernel systems using PCI P2PDMA devices are potentially impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so there are no confirmed widespread exploits as of now. The likely attack vector is local: an attacker would need to influence a PCI device that initiates a P2PDMA transfer or compromise a driver that uses iommu_dma_map_sg(). If successfully exploited, the malformed DMA length could overwrite kernel memory, causing denial of service or privilege escalation. The risk is therefore high for systems that allow untrusted drivers or devices to perform P2PDMA DMA transfers.

Generated by OpenCVE AI on August 22, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the commit correcting the scatterlist length assignment.
  • If a kernel upgrade cannot be performed immediately, restrict or disable PCI devices that use P2PDMA DMA transfers, or adjust driver configurations to avoid calling iommu_dma_map_sg() with multi‑segment scatterlists until the kernel is patched.
  • For kernel modules that perform custom scatterlist handling, add explicit checks to ensure each segment’s length is read from its own entry and validate the total length against expected values before initiating DMA.

Generated by OpenCVE AI on August 22, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-687

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-687

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path In iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length of the current scatterlist segment `s` is incorrectly assigned from the head entry `sg->length` instead of the current entry `s->length`. This typo causes all P2PDMA segments in the scatterlist to inherit the length of the first segment, leading to corrupted DMA lengths for multi- segment scatterlists. Fix this by using `s->length` instead of `sg->length`.
Title iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:45:18.964Z

Reserved: 2026-08-15T05:44:03.880Z

Link: CVE-2026-74277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:27.120

Modified: 2026-08-17T06:19:21.407

Link: CVE-2026-74277

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74277 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T01:00:13Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value