Impact
The vulnerability occurs when the dma‑heap ioctl allocation process publishes a file descriptor before ensuring that the ioctl call completed successfully. If the final copy_to_user operation fails, the descriptor remains in the caller’s file descriptor table, leaking a reference to the underlying dma_buf. This leaked descriptor can then be accessed by other threads in the same process through dup, send via SCM_RIGHTS, or other file descriptor handling primitives, potentially allowing unintended access to the dma buffer’s contents or interference with its lifecycle. The flaw represents a classic resource‑management weakness (CWE‑573), potentially compromising confidentiality or integrity of memory shared via the dma_buf interface.
Affected Systems
The flaw affects the Linux kernel’s dma‑buf subsystem, specifically the dma‑heap ioctl handling in all kernel releases that include the buggy allocation logic. Affected vendors include any implementation of the Linux kernel, such as upstream Linux distributions and derivative kernels, prior to the kernel commit that introduced the dma_buf_fd_install() helper and reordered the allocation steps.
Risk and Exploitability
Because the vulnerability is triggered by a local ioctl request that fails during a copy_to_user operation, the attack requires local privileges and the ability to manipulate the dma‑heap allocation data to cause a copy error (e.g., via mprotect). The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating a very low likelihood of exploitation in the wild. However, within a compromised or privileged local context, an attacker who can force the ioctl to fail could obtain a leaked dma_buf file descriptor and thereby gain indirect access to DMA shared memory, which may aid in privilege‑escalation or information‑exfiltration strategies.
OpenCVE Enrichment