Bug 2540527 (CVE-2026-97506) - CVE-2026-97506 kernel: crypto: ixp4xx - fix buffer chain unwind on allocation failure
Summary: CVE-2026-97506 kernel: crypto: ixp4xx - fix buffer chain unwind on allocation...
Keywords:
Status: NEW
Alias: CVE-2026-97506
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 17:07 UTC by OSIDB Bzimport
Modified: 2026-09-28 15:38 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 17:07:46 UTC
In the Linux kernel, the following vulnerability has been resolved:

crypto: ixp4xx - fix buffer chain unwind on allocation failure

chainup_buffers() builds a linked list of buffer descriptors for a
scatterlist. If dma_pool_alloc() fails while constructing the list, the
current code sets buf to NULL and later dereferences it unconditionally
at the end of the function:

  buf->next = NULL;
  buf->phys_next = 0;

This can lead to a null-pointer dereference on allocation failure.

If the failure happens after part of the descriptor chain has already
been allocated and DMA-mapped, the partially constructed chain also
needs to be released.

Fix this by terminating the partially constructed chain on allocation
failure and letting the callers unwind it via their existing cleanup
paths. Also fix ablk_perform() to preserve the hook pointers before
checking for failure, so partially built chains can be freed correctly.


Note You need to log in before you can comment on or make changes to this bug.