CVE-2026-97506
In the Linux kernel, the following vulnerability has been resolved:
crypto: ixp4xx - fix buffer chain unwind on allocation failure
chainup_buffers() builds a linked list of buffer descriptors for a scatterlist. If dma_pool_alloc() fails while constructing the list, the current code sets buf to NULL and later dereferences it unconditionally at the end of the function:
This can lead to a null-pointer dereference on allocation failure.
If the failure happens after part of the descriptor chain has already been allocated and DMA-mapped, the partially constructed chain also needs to be released.
Fix this by terminating the partially constructed chain on allocation failure and letting the callers unwind it via their existing cleanup paths.
Leer descripción completaMostrar menos
Also fix ablk_perform() to preserve the hook pointers before checking for failure, so partially built chains can be freed correctly.
Detalles técnicos trazas, registros y código del informe original
buf->next = NULL; buf->phys_next = 0;
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/028a7f4f3d69e551f6bf9f728d547bbf4cfc707d
- https://git.kernel.org/stable/c/04cb00106ca4d0fa9eca24cadc4eda6036e855c8
- https://git.kernel.org/stable/c/25056329384010a8672552b134f609601dc4f80e
- https://git.kernel.org/stable/c/4918b0bd7d2baafb45d87dca9e322137c96005c2
- https://git.kernel.org/stable/c/8c37bc8d6a6f77bf9593fb1bcab6c14c7cf02991
- https://git.kernel.org/stable/c/d4007867be42d71795b78fa7f8ce7514dda9ca83
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97506",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "d4007867be42d71795b78fa7f8ce7514dda9ca83",
"versionType": "git"
},
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "4918b0bd7d2baafb45d87dca9e322137c96005c2",
"versionType": "git"
},
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "8c37bc8d6a6f77bf9593fb1bcab6c14c7cf02991",
"versionType": "git"
},
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "04cb00106ca4d0fa9eca24cadc4eda6036e855c8",
"versionType": "git"
},
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "028a7f4f3d69e551f6bf9f728d547bbf4cfc707d",
"versionType": "git"
},
{
"status": "affected",
"version": "0d44dc59b2b434b29aafeae581d06f81efac7c83",
"lessThan": "25056329384010a8672552b134f609601dc4f80e",
"versionType": "git"
},
{
"status": "affected",
"version": "5a80273150a8a1725fa70418d106eb1f2ee8fd2f",
"versionType": "git"
},
{
"status": "affected",
"version": "82a8becb9c2c52fc5e67057a43aeded1f0731e7b",
"versionType": "git"
},
{
"status": "affected",
"version": "68845515c8b11791b547a2838e22c27dfa3115ee",
"versionType": "git"
},
{
"status": "affected",
"version": "2.6.27.22",
"lessThan": "2.6.28",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.6.28.10",
"lessThan": "2.6.29",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.6.29.3",
"lessThan": "2.6.30",
"versionType": "semver"
}
],
"programFiles": [
"drivers/crypto/intel/ixp4xx/ixp4xx_crypto.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.30",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/crypto/intel/ixp4xx/ixp4xx_crypto.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:28.423",
"references": [
{
"url": "https://git.kernel.org/stable/c/028a7f4f3d69e551f6bf9f728d547bbf4cfc707d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/04cb00106ca4d0fa9eca24cadc4eda6036e855c8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/25056329384010a8672552b134f609601dc4f80e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4918b0bd7d2baafb45d87dca9e322137c96005c2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8c37bc8d6a6f77bf9593fb1bcab6c14c7cf02991",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d4007867be42d71795b78fa7f8ce7514dda9ca83",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ixp4xx - fix buffer chain unwind on allocation failure\n\nchainup_buffers() builds a linked list of buffer descriptors for a\nscatterlist. If dma_pool_alloc() fails while constructing the list, the\ncurrent code sets buf to NULL and later dereferences it unconditionally\nat the end of the function:\n\n buf->next = NULL;\n buf->phys_next = 0;\n\nThis can lead to a null-pointer dereference on allocation failure.\n\nIf the failure happens after part of the descriptor chain has already\nbeen allocated and DMA-mapped, the partially constructed chain also\nneeds to be released.\n\nFix this by terminating the partially constructed chain on allocation\nfailure and letting the callers unwind it via their existing cleanup\npaths. Also fix ablk_perform() to preserve the hook pointers before\nchecking for failure, so partially built chains can be freed correctly."
}
],
"lastModified": "2026-10-03T11:17:59.963",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}