Impact
The dw‑edma driver in the Linux kernel contains a race condition where pause() and resume() modify channel state without acquiring vc.lock while the interrupt handler updates the same state under that lock. This unsynchronized access can cause the DMA channel to be left in an inconsistent state, recording a pause request on an already idle channel. Since no subsequent interrupt can clear this stale request, the channel becomes permanently wedged, rendering any device that relies on that DMA engine non‑functional. The impact is an availability breach that can affect kernel‑level operations dependent on that channel.
Affected Systems
All Linux kernel releases that include the dw‑edma driver are affected. Because no vendor‑specific version list is supplied, any system running a kernel with this driver may be vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Exploitation requires precise timing between user‑initiated DMA requests and interrupt handling, which generally demands local kernel‑privileged access. The vulnerability’s impact on availability is high if triggered, but the overall threat level remains low to moderate under normal conditions.
OpenCVE Enrichment
Debian DLA
Debian DSA