Description
In the Linux kernel, the following vulnerability has been resolved:

dma-direct: return struct page from dma_direct_alloc_from_pool()

Commit 5b138c534fda ("dma-direct: factor out a dma_direct_alloc_from_pool
helper") changed dma_direct_alloc_from_pool() to return the CPU address
from dma_alloc_from_pool(). That fits dma_direct_alloc(), but
dma_direct_alloc_pages() also uses the helper and expects a struct page *.

Fix this by making dma_direct_alloc_from_pool() return the struct page *
again, and pass the CPU address back through an out-parameter for the
dma_direct_alloc() caller.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

A bug in the Linux kernel’s DMA direct allocation helper caused dma_direct_alloc_from_pool() to return an improper CPU address instead of a struct page pointer. The mismatch leads to incorrect handling of page pointers during DMA allocation, which in turn can corrupt kernel memory or trigger a panic. The issue was exposed when drivers or code paths calling dma_direct_alloc_pages() interacted with the faulty helper, allowing the kernel to reference invalid memory locations.

Affected Systems

The vulnerability affects the Linux kernel, however no specific release dates are listed in the advisory. Any kernel versions compiled before the fix that still use the dma_direct_alloc_from_pool() helper are potentially impacted. The patch was integrated by committing the change in the upstream repository, so any kernel built from a tree after the commit 5b138c534fda should be safe.

Risk and Exploitability

The CVSS score of 8.8 marks it as high severity, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires the attacker to influence a privileged process that can trigger the faulty DMA allocation path, so the attack vector is local with kernel-context privileges. An attacker who can execute code in the kernel may be able to trigger memory corruption or a panic, but the narrow conditions and low exploitation probability reduce the overall risk.

Generated by OpenCVE AI on September 18, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the 5b138c534fda fix or rebuild the kernel with the patched source.
  • Verify that all drivers using dma_direct_alloc() are recompiled against the updated kernel to ensure the correct helper is used.
  • If an immediate kernel upgrade is not possible, isolate the system by disabling or uninstalling any nonessential drivers that invoke dma_direct_alloc(), and monitor for signs of kernel instability such as crashes or watchdog resets.

Generated by OpenCVE AI on September 18, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dma-direct: return struct page from dma_direct_alloc_from_pool() Commit 5b138c534fda ("dma-direct: factor out a dma_direct_alloc_from_pool helper") changed dma_direct_alloc_from_pool() to return the CPU address from dma_alloc_from_pool(). That fits dma_direct_alloc(), but dma_direct_alloc_pages() also uses the helper and expects a struct page *. Fix this by making dma_direct_alloc_from_pool() return the struct page * again, and pass the CPU address back through an out-parameter for the dma_direct_alloc() caller.
Title dma-direct: return struct page from dma_direct_alloc_from_pool()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:10.079Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.707

Modified: 2026-09-16T15:18:23.157

Link: CVE-2026-89995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses