Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: fsl-edma: tracing: no ptr dereference during log output

The fsl edma events store a pointer to a struct fsl_edma_engine in the
ringbuffer and dereference it when a log entry is printed. At this time,
the pointer may no longer be valid.

Event injection can be used to trigger a crash:

$ cd /sys/kernel/tracing
$ echo 'value = 0' > events/fsl_edma/edma_writeb/inject
$ cat trace

The log output needs only edma->membase. Add a membase field at the end
of the event and use the new field for log output. Keep the existing
fields for backward compatibility.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

In the Linux kernel, the fsl‑edma tracing code stores a pointer to a struct fsl_edma_engine within a ringbuffer and dereferences that pointer when a trace log entry is printed. If the engine has already been freed or its memory relocated when the log is generated, the dereference accesses an invalid address, causing a kernel panic. An attacker can trigger the crash by injecting a malformed event into the fsl_edma trace buffer through the /sys/kernel/tracing interface, resulting in a denial‑of‑service for the entire kernel and any user processes.

Affected Systems

The flaw exists in any Linux kernel that includes the fsl edma driver with tracing enabled, regardless of distribution. All current kernels before the fix are affected, as the issue was corrected by adding a membase field for log output and avoiding the pointer dereference. Distributions shipping those kernels without the patch are vulnerable until a newer kernel release is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and it requires local privileged access to the tracing interface (root or similar) to inject events, making it an attack vector that is local rather than remote. A successful exploit would crash the kernel, causing a system‑wide denial of service.

Generated by OpenCVE AI on September 18, 2026 at 08:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fsl edma tracing fix.
  • Disable the fsl edma trace event by unmounting or removing /sys/kernel/tracing from the system to block event injection.
  • Restrict write permissions on /sys/kernel/tracing so that only privileged users can inject events, preventing low‑level attack vectors.

Generated by OpenCVE AI on September 18, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference during log output The fsl edma events store a pointer to a struct fsl_edma_engine in the ringbuffer and dereference it when a log entry is printed. At this time, the pointer may no longer be valid. Event injection can be used to trigger a crash: $ cd /sys/kernel/tracing $ echo 'value = 0' > events/fsl_edma/edma_writeb/inject $ cat trace The log output needs only edma->membase. Add a membase field at the end of the event and use the new field for log output. Keep the existing fields for backward compatibility.
Title dmaengine: fsl-edma: tracing: no ptr dereference during log output
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:08.470Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89994

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.593

Modified: 2026-09-16T15:18:23.037

Link: CVE-2026-89994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses