Description
In the Linux kernel, the following vulnerability has been resolved:

hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device

The OMAP SSI driver uses a synthetic HSI controller device allocated via
hsi_alloc_controller(), which does not go through the normal OF/platform
device initialization path.

As a result, the embedded struct device does not have a DMA mask
initialized by default.

After recent DMA API hardening changes, dma_map_sg() and related helpers
now require a valid dma_mask to be present, otherwise the driver may
crash or trigger warnings when attempting DMA mapping operations.

Fix this by explicitly initializing the DMA mask for the SSI controller
device and setting a 32-bit DMA mask, which matches the hardware
capabilities.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The OMAP SSI driver in the Linux kernel allocates a synthetic HSI controller via hsi_alloc flow. The allocated device does not receive a the DMA API requires a valid dma_mask for every DMA mapping operation. Because the mask is missing, attempts to map DMA buffers with dma_map_sg() or related helpers can cause a kernel crash or generate warnings, leading to a denial‑of‑service for any process using the driver.

Affected Systems

All Linux kernel builds that include the O. The vulnerability is present in any kernel version where the driver is compiled and the DMA API hardening changes are in effect. Vendors that ship kernels with the unpatched driver expose their systems to this risk.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local: an attacker would need to trigger a DMA mapping operation within the SSI driver, which requires local code execution or a separate kernel flaw that provides such control. Thus the risk is local denial of service, with potential to aid privilege escalation if combined with other weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 21:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the DMA mask initialization for the OMAP SSI driver.
  • If a kernel upgrade is not feasible, disable or unload the OMAP SSI driver to prevent uninitialized DMA usage.
  • If disabling the driver is impractical, restrict DMA operations by configuring the system to use non‑DMA paths for the SSI device until the patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-909
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device The OMAP SSI driver uses a synthetic HSI controller device allocated via hsi_alloc_controller(), which does not go through the normal OF/platform device initialization path. As a result, the embedded struct device does not have a DMA mask initialized by default. After recent DMA API hardening changes, dma_map_sg() and related helpers now require a valid dma_mask to be present, otherwise the driver may crash or trigger warnings when attempting DMA mapping operations. Fix this by explicitly initializing the DMA mask for the SSI controller device and setting a 32-bit DMA mask, which matches the hardware capabilities.
Title hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:17.110Z

Reserved: 2026-09-11T19:38:34.730Z

Link: CVE-2026-89594

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:44.040

Modified: 2026-09-14T13:19:13.330

Link: CVE-2026-89594

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:57Z

Links: CVE-2026-89594 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-909

    Missing Initialization of Resource