Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Initialize IRQ data before requesting IRQs

dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before
dw_edma_channel_setup() fills the back pointer. A shared interrupt can
therefore enter the handler with dw_irq->dw still NULL, leading to a
NULL pointer dereference.

Set the back pointer before installing each handler.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Crash
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, an initialization oversight in the dw‑edma driver causes an IRQ handler to be registered with a null back pointer. When a shared interrupt fires, the handler dereferences this null pointer, which results in a kernel crash. The failure leads to a denial‑of‑service condition for the affected system. The weakness is a null pointer dereference, characteristic of improper initialization.

Affected Systems

The affected product is the Linux kernel, specifically the dw‑edma DMA engine driver. No explicit kernel version range is given, so any kernel build that includes this driver before the patch may be vulnerable. Linux distributions that ship the upstream kernel without the update are at risk.

Risk and Exploitability

The available assessment shows a negligible exploitation probability with an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and no commercial CVSS score is supplied, making detailed severity unclear. Attackers would need local access to trigger the driver’s shared interrupt or rely on a scenario that causes the interrupt to deliver a request, which is typically an administrative or privileged context. The impact remains a system crash rather than arbitrary code execution, based on the kernel’s reaction to a null pointer dereference. Therefore, systems exposed to this driver should treat the vulnerability as low likelihood but potentially disruptive to availability.

Generated by OpenCVE AI on September 18, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that sets the back pointer before IRQ handler installation.
  • If a kernel update is not possible, disable or unload the dw‑edma driver and block access to the corresponding hardware until the patch is applied.
  • Verify that any services or applications that request DW‑EDMA IRQs are not exposed to untrusted input and consider applying kernel hardening measures if available.

Generated by OpenCVE AI on September 18, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-665

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Initialize IRQ data before requesting IRQs dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference. Set the back pointer before installing each handler.
Title dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:06.611Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89993

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.470

Modified: 2026-09-16T11:17:10.470

Link: CVE-2026-89993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses