Linux Kernel Vulnerability in PXA DMA Engine Allocation
CVE-2026-98324

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98324?

A flaw in the Linux kernel's handling of DMA engine descriptor allocation has been identified, leading to improper resource management. The function pxad_alloc_desc() was inadvertently modified to double count hardware descriptors due to incorrect handling in the code. Specifically, the transition from kzalloc to kzalloc_flex introduced a counting inconsistency, prompting incorrect increments of descriptor counts. This could cause pxad_free_desc() to erroneously free entries that weren't allocated, resulting in potential instability and unexpected behavior in systems utilizing these descriptors.

Affected Version(s)

Linux 69050f8d6d075dc01af7a5f2f550a8067510366f < 1de93785f32b450e9eae1e4fcfb7d03eb49eb27e

Linux 69050f8d6d075dc01af7a5f2f550a8067510366f

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.