In the Linux kernel, the following vulnerability has been resolved:
iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
In iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length
of the current scatterlist segment `s` is incorrectly assigned from the
head entry `sg->length` instead of the current entry `s->length`.
This typo causes all P2PDMA segments in the scatterlist to inherit the
length of the first segment, leading to corrupted DMA lengths for multi-
segment scatterlists.
Fix this by using `s->length` instead of `sg->length`.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 06:22
Updated : 2026-08-17 06:19
NVD link : CVE-2026-74277
Mitre link : CVE-2026-74277
CVE.ORG link : CVE-2026-74277
JSON object : View
Products Affected
No product.
CWE
No CWE.
