Description
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers

Fix a race condition in AXIDMA and MCDMA irq handlers where the channel
could be incorrectly marked as idle and attempt spurious transfers when
descriptors are still being processed.

The issue occurs when:
1. Multiple descriptors are queued and active.
2. An interrupt fires after completing some descriptors.
3. xilinx_dma_complete_descriptor() moves completed descriptors to
done_list.
4. Channel is marked idle and start_transfer() is called even though
active_list still contains unprocessed descriptors.
5. This leads to premature transfer attempts and potential descriptor
corruption or missed completions.

Only mark the channel as idle and start new transfers when the active list
is actually empty, ensuring proper channel state management and avoiding
spurious transfer attempts.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Corruption
Action: Immediate Patch
AI Analysis

Impact

A race condition exists within the Xilinx AXIDMA and MCDMA interrupt handlers of the Linux kernel. The channel could be incorrectly marked idle while descriptors are still active, causing the driver to initiate new transfers prematurely. This leads to descriptor corruption or missed completions, jeopardizing the integrity of data being moved through the DMA engine. The vulnerability’s weakness is a concurrent execution race condition that allows unsafe state changes during interrupt handling.

Affected Systems

All Linux kernel versions that contain the Xilinx DMA driver without the patch referenced in the CVE, including the branches that use the AXIDMA and MCDMA engines. The exact affected releases are not enumerated, but any kernel that incorporates the vulnerable driver before the fix would be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity of potential impact, yet the EPSS score of less than 1% implies a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and the typical attack vector would be local privileged access that can queue or manipulate DMA descriptors. Although the exploitability is limited by the need for kernel-space interaction, successful exploitation would result in data corruption or loss of service, making it a significant risk for systems relying on DMA operations.

Generated by OpenCVE AI on September 19, 2026 at 15:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that resolves the race condition, such as the commit 0b6d055edb55ecadadf54e930c2b4fab76fa9a5a or any later merge that includes the fix.
  • Upgrade the system to a kernel version that contains the patched Xilinx DMA driver, ensuring the latest stable release is running.
  • If a patch or newer kernel cannot be applied immediately, consider disabling or blacklisting the Xilinx DMA driver to prevent spurious channel state changes until a fix is available.
  • Verify that all DMA queues are properly drained and that no active descriptors remain when the kernel is shutting down or updating the driver to mitigate side effects.

Generated by OpenCVE AI on September 19, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Fix a race condition in AXIDMA and MCDMA irq handlers where the channel could be incorrectly marked as idle and attempt spurious transfers when descriptors are still being processed. The issue occurs when: 1. Multiple descriptors are queued and active. 2. An interrupt fires after completing some descriptors. 3. xilinx_dma_complete_descriptor() moves completed descriptors to done_list. 4. Channel is marked idle and start_transfer() is called even though active_list still contains unprocessed descriptors. 5. This leads to premature transfer attempts and potential descriptor corruption or missed completions. Only mark the channel as idle and start new transfers when the active list is actually empty, ensuring proper channel state management and avoiding spurious transfer attempts.
Title dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:19.469Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93170

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:12.700

Modified: 2026-09-18T18:18:23.360

Link: CVE-2026-93170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')