Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma-pcie: Reject devices without driver data

dw_edma_pcie_probe() treats the PCI device ID driver_data as the
template for the controller layout and copies it unconditionally. A
device bound dynamically via sysfs can match the driver without that
data, which leads to a NULL pointer dereference.

Reject such matches before enabling the device.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s dw_edma_pcie driver contains a flaw in the probe function: it copies the PCI device ID’s driver_data into the controller layout without verifying that this data is present. When a device that lacks driver_data is bound to the driver via sysfs, the copy operation dereferences a NULL pointer, causing a kernel panic and a system reboot. This results in a denial of service.

Affected Systems

Any Linux kernel that incorporates the dw_edma_pcie driver and has not applied the patch commit that protects against the NULL pointer dereference is affected. No specific version range is listed, so all kernel releases preceding the fix are potentially vulnerable.

Risk and Exploitability

The EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The CVSS score of 5.5 reflects a medium severity risk. The attack vector is local: an attacker must have the ability to write to the sysfs entry /sys/bus/pci/drivers/dw_edma_pcie/bind. This typically requires privileged (root) access, so the risk is moderate to high for users with such access. If exploited, the kernel will crash, yielding a full system reboot and denial of service.

Generated by OpenCVE AI on August 22, 2026 at 10:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the fix for the dw_edma_pcie probe NULL pointer dereference.
  • If a kernel upgrade is not immediately possible, limit write permissions on /sys/bus/pci and /sys/bus/pci/drivers/dw_edma_pcie to prevent unauthorized device binding. The restriction mitigates the local privilege requirement for the exploit.
  • Continuously monitor system logs for kernel panic events related to dw_edma_pcie and audit PCI device binding activity to detect and respond to attempted exploitation.

Generated by OpenCVE AI on August 22, 2026 at 10:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma-pcie: Reject devices without driver data dw_edma_pcie_probe() treats the PCI device ID driver_data as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference. Reject such matches before enabling the device.
Title dmaengine: dw-edma-pcie: Reject devices without driver data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:09:06.340Z

Reserved: 2026-08-09T03:40:39.908Z

Link: CVE-2026-72147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:32.373

Modified: 2026-08-17T06:18:14.800

Link: CVE-2026-72147

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72147 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:15:04Z

Weaknesses