Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK

The DONE_INT_MASK and ABORT_INT_MASK registers are shared by all DMA
channels, and modifying them requires a read-modify-write sequence.
Because this operation is not atomic, concurrent calls to
dw_edma_v0_core_start() can introduce race conditions if two channels
update these registers simultaneously.

Add a spinlock to serialize access to these registers and prevent race
conditions.

[den: update dw_edma.lock comment]
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The dw_edma driver in the Linux kernel performs a non‑atomic read‑modify‑write on two shared register masks used for DMA interrupts. When dw_edma_v0_core_start() is called concurrently on multiple DMA channels, the missing synchronization causes a race condition that can corrupt the DONE_INT_MASK and ABORT_INT_MASK values and lead to incorrect DMA operation or system instability. This vulnerability is a race condition involving improper synchronization (CWE-820).

Affected Systems

Any Linux system running a kernel that includes the dw_edma driver before the spinlock fix is applied is vulnerable. The vendor product list indicates Linux kernels, and no version range is specified, so all affected kernels containing the driver at the time of the commit are considered susceptible until the patch is installed.

Risk and Exploitability

The CVSS base score of 8.8 reflects high severity. The EPSS score of less than 1% and the absence from the KEV catalog suggest that public exploits are unlikely. Propagation likely requires a locally running process that can initiate concurrent DMA channel starts; remote exploitation is not described in the data.

Generated by OpenCVE AI on August 22, 2026 at 11:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that includes the spinlock patch for the dw_edma driver.
  • If an updated kernel is unavailable, disable the dw_edma driver or restrict its use to trusted processes to prevent overlapping register writes.
  • Monitor kernel logs and DMA‑related metrics for abnormal interrupt mask changes or driver errors, and apply additional isolation measures if suspicious activity occurs.

Generated by OpenCVE AI on August 22, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 13:15:00 +0000


Sat, 22 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-820
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H'}


Sat, 15 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK The DONE_INT_MASK and ABORT_INT_MASK registers are shared by all DMA channels, and modifying them requires a read-modify-write sequence. Because this operation is not atomic, concurrent calls to dw_edma_v0_core_start() can introduce race conditions if two channels update these registers simultaneously. Add a spinlock to serialize access to these registers and prevent race conditions. [den: update dw_edma.lock comment]
Title dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:46:52.752Z

Reserved: 2026-08-09T03:40:39.908Z

Link: CVE-2026-72148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:32.483

Modified: 2026-08-23T13:16:40.570

Link: CVE-2026-72148

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72148 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:30:17Z

Weaknesses