๐Ÿ” CVE Alert

CVE-2026-98254

UNKNOWN 0.0

swiotlb: use the adjusted address for the highmem page lookup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: swiotlb: use the adjusted address for the highmem page lookup swiotlb_bounce() reads the page frame number from the slot's recorded orig_addr, then advances orig_addr by tlb_offset to reach the address the caller asked about. The highmem branch mixes the two: the offset within the page comes from the adjusted address, the page from the value before it. Once the adjustment crosses a page boundary the pair no longer describes one location, and the whole copy lands one page below the intended one for a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE writes the device data over the wrong page and leaves the intended one stale, DMA_TO_DEVICE feeds the device from a page the mapping may not cover. Partial syncs through dma_sync_single_range_for_*() are what make tlb_offset non-zero. The branch test is picked the same way, so a slot recorded in lowmem can be adjusted into highmem and the lowmem path then hands a highmem address to phys_to_virt(). Take both from orig_addr once it is final and keep pfn in the branch that uses it. PhysHighMem() asks the question straight from the address, as dma-debug already does.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5f89468e2f060031cd89fd4287298e0eaf246bf6 < 6e53b4d6afbde626255805d438cabb1cac482445 5f89468e2f060031cd89fd4287298e0eaf246bf6 < aa4709813b29db89f2307f968db5d24925dcdeb1 5f89468e2f060031cd89fd4287298e0eaf246bf6 < 0219b72f5c209732b2f03a8cc0d7240b5e428a99 5f89468e2f060031cd89fd4287298e0eaf246bf6 < b7d7914a9ae3097e63d113007e4fb44d33d515b1 e6108147dd91b94d1979b110f265710c254c99d5 e77b796eb9b7ca3c1c0d574d0c155f55b59ca8d5 5.10.47 < 5.11 5.12.14 < 5.13
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6e53b4d6afbde626255805d438cabb1cac482445 git.kernel.org: https://git.kernel.org/stable/c/aa4709813b29db89f2307f968db5d24925dcdeb1 git.kernel.org: https://git.kernel.org/stable/c/0219b72f5c209732b2f03a8cc0d7240b5e428a99 git.kernel.org: https://git.kernel.org/stable/c/b7d7914a9ae3097e63d113007e4fb44d33d515b1