Bug 2516254 (CVE-2026-68466)

Summary: CVE-2026-68466 kernel: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's `lpc32xx_slc` driver, which manages NAND flash memory. This vulnerability occurs because the driver fails to properly handle Direct Memory Access (DMA) transfer timeouts. When a DMA transfer times out, the driver incorrectly reports it as successful and unmaps the associated memory buffer without terminating the DMA channel. This can lead to the system attempting to access an unmapped memory region, potentially causing data corruption or system instability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-15 06:02:53 UTC
In the Linux kernel, the following vulnerability has been resolved:

mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout

lpc32xx_xmit_dma() waits for the DMA completion callback but ignores
wait_for_completion_timeout(). A timed out DMA transfer is therefore
unmapped and reported as successful to the NAND read/write path.

Return -ETIMEDOUT when the completion wait expires. Terminate the DMA
channel before unmapping the scatterlist so the timed out transfer cannot
continue to access the buffer after the error is returned.