Description
In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Tie IIO dma fence lock lifetime to the fence

The `iio_dma_fence` implementation currently uses a lock embedded in the
`iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the
`iio_dmabuf_priv`, which can cause a use-after-free.

Tie the lifetime of the lock to the lifetime of the fence by embedding them
in the same struct.

We can't just hold a reference to the `iio_dmabuf_priv` from the
`iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the
fence release callback is not allowed to sleep.

Note that the `dma_fence` framework now has an internal lock that gets used
when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to
allow this patch to be backportable use an external lock.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a use‑after‑free condition caused by the lock in the IIO DMA fence outliving the DMA buffer private structure. When the fence calls back after the buffer has been released, it accesses freed memory, which can lead to corruption of critical data or code paths. An attacker who can trigger this scenario could potentially overwrite memory with attacker‑supplied content, escalating privileges or causing a crash.

Affected Systems

The affected vendor is the Linux kernel, impacting all kernel versions that include the IIO buffer subsystem prior to the applied patch. No specific version list was given, so any Linux kernel builds that contain the unpatched IIO DMA fence implementation are potentially affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of active exploitation at present. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or through privileged access to the IIO buffer subsystem; an attacker would need to influence the lifecycle of the fence and the buffer, a scenario that is feasible for privileged users or compromised firmware.

Generated by OpenCVE AI on September 18, 2026 at 08:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the upstream patch tying the lock lifetime to the DMA fence, eliminating the use‑after‑free flaw.
  • If an updated kernel cannot be applied immediately, permanently disable or restrict user access to the IIO buffer interfaces so that no user can create or release DMA buffers that could trigger the flaw.
  • Monitor vendor releases for backport or security patches that address the IIO DMA fence implementation and plan an upgrade as soon as a safe kernel version becomes available.

Generated by OpenCVE AI on September 18, 2026 at 08:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Tie IIO dma fence lock lifetime to the fence The `iio_dma_fence` implementation currently uses a lock embedded in the `iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the `iio_dmabuf_priv`, which can cause a use-after-free. Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct. We can't just hold a reference to the `iio_dmabuf_priv` from the `iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the fence release callback is not allowed to sleep. Note that the `dma_fence` framework now has an internal lock that gets used when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to allow this patch to be backportable use an external lock.
Title iio: buffer: Tie IIO dma fence lock lifetime to the fence
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:26.549Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.610

Modified: 2026-09-16T15:18:19.340

Link: CVE-2026-89940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:30:15Z

Weaknesses