CRITICAL Introduced in 4.11
crypto DMACleanup Leak
CVE-2026-74279
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI4.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong loop index The sg_cleanup error path used list[i] instead of list[j] when unmapping DMA buffers, leaking successfully mapped entries and repeatedly unmapping the failed one.
02KernelScan AI Analysis
Risk summary
A DMA cleanup error path in the Cavium CPT crypto driver uses the wrong loop index, leaking successfully-mapped DMA buffers and repeatedly unmapping the failed entry. An unprivileged local user can trigger this through the kernel crypto API (e.g., AF_ALG sockets) on systems equipped with Cavium Octeon-TX hardware, causing progressive DMA memory exhaustion that can degrade or halt cryptographic operations.
Vulnerability analysis
In the Cavium CPT crypto accelerator driver, the error cleanup path that unmaps DMA scatter-gather buffers uses the wrong loop index variable, causing it to skip unmapping all successfully-mapped entries (leaking their DMA mappings) and instead repeatedly attempt to unmap the single entry that already failed. This error path is reached when a DMA mapping fails partway through setup, which can be induced under memory pressure. The kernel crypto API is accessible to unprivileged local users via AF_ALG sockets on systems with Cavium Octeon-TX hardware, making the leak triggerable without special privileges. The fix corrects the loop index so each successfully-mapped buffer is properly unmapped during cleanup, preventing both the resource leak and the redundant unmapping of the failed entry.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 4.11 | 5.10.261 | 23c6174e48f6 |
| 5.15 | 4.11 | 5.15.212 | 23d3a7e896a1 |
| 6.1 | 4.11 | 6.1.178 | 28141f95ae93 |
| 6.12 | 4.11 | 6.12.97 | 3b8a1e1f4e40 |
| 6.18 | 4.11 | 6.18.40 | fb4d57b83356 |
| mainline | 4.11 | 7.2-rc1 | 9dbf173bd32d |
| 6.6 | 4.11 | 6.6.145 | 8afd1007ef79 |
| 7.1 | 4.11 | 7.1.5 | d319b83b97b3 |