Answer in brief
CVE-2026-98298 records a Unknown severity vulnerability in dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <f448a5f5bd10d792440a1b08cf2e8f311767032d || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <2148db529f082d6e3ca95413bf943442f4ef30cc || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <d920c07aa6d89ec11afdb6976aafaee9563a5234 || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <4a33886057e6d127555efb022879c583e966acc5 || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <88a505330eb06128f7ce79a4c5e4832b7601b3d1 || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <bae65e4925928f77824ca0103122e2ed20ef5802 || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <54ccc01012a240476edf641bf1a2b8bff54fe6ae || >=c8acd6aa6bed3c0fd7898202f4ebc534db9085f2 <075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 | f448a5f5bd10d792440a1b08cf2e8f311767032d, 2148db529f082d6e3ca95413bf943442f4ef30cc, d920c07aa6d89ec11afdb6976aafaee9563a5234, 4a33886057e6d127555efb022879c583e966acc5, 88a505330eb06128f7ce79a4c5e4832b7601b3d1, bae65e4925928f77824ca0103122e2ed20ef5802, 54ccc01012a240476edf641bf1a2b8bff54fe6ae, 075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 |
| Linux/Linuxgeneric | 3.7 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist putting each entry into 'sg', but the entry length is read from 'sgl' (the list head) instead of 'sg' (the current entry): for_each_sg(sgl, sg, sg_len, i) { addr = sg_dma_address(sg); avail = sg_dma_len(sgl); /* should be 'sg' */ Consequently 'avail' is always the length of the first entry. For multi-sg lists this causes out-of-bounds reads when a later entry is shorter than the first, and silent data loss when it is longer. Single-sg or uniformly-sized lists happen to mask the issue.
Quoted source text, attributed separately from HOL analysis.