Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Terminate all descriptors without callbacks

The DMA Engine client documentation says in the "Terminate APIs" section
of Documentation/driver-api/dmaengine/client.rst:

"No callback functions will be called for any incomplete transfers."

dw-edma instead calls vchan_cookie_complete() when a deferred STOP reaches
the interrupt handler. This schedules a callback for the active descriptor
and leaves other issued or submitted descriptors queued. A late callback
after dmaengine_terminate_sync() can dereference client state that has
already been freed, while leftover descriptors may later restart into
reused buffers or leak.

Move all issued and submitted descriptors to the terminated list whenever
termination completes. For a pending STOP, do this from both the DONE and
ABORT paths. Complete their cookies in order without scheduling callbacks.

A STOP can remain pending until the running transfer raises an
interrupt. Make device_synchronize() wait for such a pending STOP to
complete before releasing terminated descriptors. Reuse it from
free_chan_resources(), then release the remaining virt-dma resources.
Sleep instead of busy-polling while waiting, and warn if the existing
timeout expires.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation or Denial of Service via use‑after‑free in DMA engine
Action: Patch
AI Analysis

Impact

In Linux kernel drivers that implement the dw‑edma DMA engine, terminating a transfer incorrectly fails to complete all descriptor callbacks. The driver leaves issued or pending descriptors queued, and later calls the completion routine after the client state has already been freed. This produces a use‑after‑free condition that can corrupt kernel memory, lead to a crash, or allow a local attacker to execute code with kernel privileges. The flaw also permits leftover descriptors to be re‑issued into reused buffers, which can leak memory or cause indeterminate behavior.

Affected Systems

All Linux kernel configurations that include the dw‑edma driver are affected. The flaw exists in the generic Linux kernel repository; any vendor releases that ship the dw‑edma driver without applying the upstream patch are vulnerable. No specific kernel version is listed, so any build that has not applied the fix and contains the dw‑edma driver is considered at risk.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS score is below 1%, indicating that exploitation is considered rare at this time, and the vulnerability is not listed in the CISA KEV catalog. A successful exploit would require the attacker to control DMA operations, which is typically a local privileged user or an attacker with physical access to the device. The attack vector is inferred to be local or through compromised DMA clients; no remote exploitation path is reported in the description.

Generated by OpenCVE AI on September 19, 2026 at 23:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel updated with the dw‑edma termination fix as provided by the upstream repository.
  • If patching is not immediately possible, disable or restrict access to the DMA engine for untrusted clients, and avoid initiating DMA transfers that could trigger the termination path until a patch is applied.
  • Implement kernel hardening measures such as CONFIG_DYNAMIC_KMEM or uprobe‑based tamper detection to mitigate the use‑after‑free risk while awaiting an official fix.

Generated by OpenCVE AI on September 19, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without callbacks The DMA Engine client documentation says in the "Terminate APIs" section of Documentation/driver-api/dmaengine/client.rst: "No callback functions will be called for any incomplete transfers." dw-edma instead calls vchan_cookie_complete() when a deferred STOP reaches the interrupt handler. This schedules a callback for the active descriptor and leaves other issued or submitted descriptors queued. A late callback after dmaengine_terminate_sync() can dereference client state that has already been freed, while leftover descriptors may later restart into reused buffers or leak. Move all issued and submitted descriptors to the terminated list whenever termination completes. For a pending STOP, do this from both the DONE and ABORT paths. Complete their cookies in order without scheduling callbacks. A STOP can remain pending until the running transfer raises an interrupt. Make device_synchronize() wait for such a pending STOP to complete before releasing terminated descriptors. Reuse it from free_chan_resources(), then release the remaining virt-dma resources. Sleep instead of busy-polling while waiting, and warn if the existing timeout expires.
Title dmaengine: dw-edma: Terminate all descriptors without callbacks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:44.317Z

Reserved: 2026-09-17T15:57:05.657Z

Link: CVE-2026-93042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.420

Modified: 2026-09-18T18:18:18.930

Link: CVE-2026-93042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses