7.8

CVE-2026-98254

swiotlb: use the adjusted address for the highmem page lookup

In the Linux kernel, the following vulnerability has been resolved:

swiotlb: use the adjusted address for the highmem page lookup

swiotlb_bounce() reads the page frame number from the slot's recorded
orig_addr, then advances orig_addr by tlb_offset to reach the address
the caller asked about. The highmem branch mixes the two: the offset
within the page comes from the adjusted address, the page from the value
before it.

Once the adjustment crosses a page boundary the pair no longer describes
one location, and the whole copy lands one page below the intended one
for a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE
writes the device data over the wrong page and leaves the intended one
stale, DMA_TO_DEVICE feeds the device from a page the mapping may not
cover. Partial syncs through dma_sync_single_range_for_*() are what make
tlb_offset non-zero.

The branch test is picked the same way, so a slot recorded in lowmem can
be adjusted into highmem and the lowmem path then hands a highmem
address to phys_to_virt().

Take both from orig_addr once it is final and keep pfn in the branch
that uses it. PhysHighMem() asks the question straight from the address,
as dma-debug already does.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5f89468e2f060031cd89fd4287298e0eaf246bf6
Version < 6e53b4d6afbde626255805d438cabb1cac482445
Status affected
Version 5f89468e2f060031cd89fd4287298e0eaf246bf6
Version < aa4709813b29db89f2307f968db5d24925dcdeb1
Status affected
Version 5f89468e2f060031cd89fd4287298e0eaf246bf6
Version < 0219b72f5c209732b2f03a8cc0d7240b5e428a99
Status affected
Version 5f89468e2f060031cd89fd4287298e0eaf246bf6
Version < b7d7914a9ae3097e63d113007e4fb44d33d515b1
Status affected
Version e6108147dd91b94d1979b110f265710c254c99d5
Status affected
Version e77b796eb9b7ca3c1c0d574d0c155f55b59ca8d5
Status affected
Version 5.10.47
Version < 5.11
Status affected
Version 5.12.14
Version < 5.13
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6e53b4d6afbde626255805d438cabb1cac482445
https://git.kernel.org/stable/c/aa4709813b29db89f2307f968db5d24925dcdeb1
https://git.kernel.org/stable/c/0219b72f5c209732b2f03a8cc0d7240b5e428a99
https://git.kernel.org/stable/c/b7d7914a9ae3097e63d113007e4fb44d33d515b1