Executive brief
The Linux kernel contains a typo in the IOMMU DMA mapping code that handles peer-to-peer (P2P) PCI transfers. When processing multiple memory segments, the code incorrectly reuses the length of the first segment for all subsequent segments, causing DMA operations to transfer wrong amounts of data. This can lead to data corruption, device hangs, or system crashes in applications using P2P transfers.
Technical details
The vulnerability is a variable reference error in the iommu_dma_map_sg() function in drivers/iommu/dma-iommu.c. When handling PCI P2PDMA cases, the code assigns the DMA length from the wrong scatterlist entry: it reads from the head pointer `sg->length` instead of the current segment `s->length`. This causes all P2PDMA segments in a multi-segment scatterlist to inherit the length of the first segment, corrupting DMA lengths for subsequent entries. The fix is a one-line change replacing `sg->length` with `s->length` at line 1468. No authentication or user interaction is required; exploitation occurs automatically when P2PDMA transfers process multi-segment scatterlists. Patch is available in upstream kernel and stable branches.
Affected products
- Linux Linux kernel Linux 5.10 through 6.18 and later
Timeline
- 2026-08-15: disclosed
- 2026-06-12: patched: Upstream patch db50fb87015b955a5a0c155293b2dd40d63a3b9e
- 2026-07-24: patched: Stable kernel backport 8646f00ce021e49f4f05bc1d4060a0c27b25d0e1