Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Serialize abort state updates

dw_edma_abort_interrupt() drops vc.lock before changing request and
status. issue_pending() can acquire the lock in that small window,
observe the old busy state, and skip starting queued descriptors. Then
the abort handler overwrites the channel status as idle, leaving the new
descriptors stranded for good.

Keep descriptor completion and the state transition in the same critical
section.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service caused by stranded DMA descriptors
Action: Patch
AI Analysis

Impact

In the Linux kernel's DMA engine, an accidental race condition was found in the dw_edma abort handler. The abort function releases a lock before it changes the request and status fields. During that narrow window the helper routine can acquire the lock, see the old busy state, and skip starting queued descriptors. The abort handler then reports the channel as idle, leaving any new descriptors in limbo. The result is that DMA operations never complete, which can stall services that depend on the DMA engine and potentially hang the system.

Affected Systems

The flaw exists in all Linux kernels that use the dw_edma DMA driver from the Linux vendor. No specific kernel versions were listed, so the vulnerability may affect any build using the default dw_edma driver.

Risk and Exploitability

The EPSS score for this flaw is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The described race requires an entity that can trigger an abort on the dw_edma channel, which usually implies local privileged access. No evidence of remote exploitation is provided, but the lack of a security boundary makes the flaw potentially useful for privilege‑escalation or denial‑of‑service attacks within a kernel.

Generated by OpenCVE AI on September 19, 2026 at 06:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the dw_edma fix.
  • If no update is available, remove or disable the dw_edma DMA engine from the kernel configuration until a patch is released.
  • Avoid initiating DMA transactions that rely on dw_edma while the kernel is at risk.
  • Reboot the system after applying any of the above changes to ensure the old state is cleared.

Generated by OpenCVE AI on September 19, 2026 at 06:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize abort state updates dw_edma_abort_interrupt() drops vc.lock before changing request and status. issue_pending() can acquire the lock in that small window, observe the old busy state, and skip starting queued descriptors. Then the abort handler overwrites the channel status as idle, leaving the new descriptors stranded for good. Keep descriptor completion and the state transition in the same critical section.
Title dmaengine: dw-edma: Serialize abort state updates
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:34.232Z

Reserved: 2026-09-17T15:57:05.657Z

Link: CVE-2026-93041

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.250

Modified: 2026-09-17T17:17:57.250

Link: CVE-2026-93041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:45:16Z

Weaknesses
  • CWE-368

    Context Switching Race Condition