Impact
In Linux kernel drivers that implement the dw‑edma DMA engine, terminating a transfer incorrectly fails to complete all descriptor callbacks. The driver leaves issued or pending descriptors queued, and later calls the completion routine after the client state has already been freed. This produces a use‑after‑free condition that can corrupt kernel memory, lead to a crash, or allow a local attacker to execute code with kernel privileges. The flaw also permits leftover descriptors to be re‑issued into reused buffers, which can leak memory or cause indeterminate behavior.
Affected Systems
All Linux kernel configurations that include the dw‑edma driver are affected. The flaw exists in the generic Linux kernel repository; any vendor releases that ship the dw‑edma driver without applying the upstream patch are vulnerable. No specific kernel version is listed, so any build that has not applied the fix and contains the dw‑edma driver is considered at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS score is below 1%, indicating that exploitation is considered rare at this time, and the vulnerability is not listed in the CISA KEV catalog. A successful exploit would require the attacker to control DMA operations, which is typically a local privileged user or an attacker with physical access to the device. The attack vector is inferred to be local or through compromised DMA clients; no remote exploitation path is reported in the description.
OpenCVE Enrichment
Debian DLA
Debian DSA