{"id":"AZL-106131","summary":"CVE-2026-98298 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()\n\nIn mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist\nputting each entry into 'sg', but the entry length is read from 'sgl'\n(the list head) instead of 'sg' (the current entry):\n\n    for_each_sg(sgl, sg, sg_len, i) {\n        addr = sg_dma_address(sg);\n        avail = sg_dma_len(sgl);   /* should be 'sg' */\n\nConsequently 'avail' is always the length of the first entry. For\nmulti-sg lists this causes out-of-bounds reads when a later entry is\nshorter than the first, and silent data loss when it is longer.\nSingle-sg or uniformly-sized lists happen to mask the issue.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:20Z","upstream":["CVE-2026-98298"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98298"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106131.json"}}],"schema_version":"1.9.0"}