Back

CRITICAL

crypto: iaa - unmap dst before software fallback on decompress

Published Sep 11, 2026

Description

On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the stale bounce buffer over req->dst, corrupting the result.

Unmap before the fallback runs. The async path unmaps inline; the sync path signals the retry with -EAGAIN so iaa_comp_adecompress() runs the fallback after unmapping.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 21, 2026
Reserved Aug 26, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Sep 13, 2026

Red Hat

Severity Moderate
Public date Sep 11, 2026
Bugzilla 2532217

ENISA EUVD

Assigner Linux
Published Sep 11, 2026
Updated Sep 21, 2026

GitHub

No data