Impact
A race condition exists within the Xilinx AXIDMA and MCDMA interrupt handlers of the Linux kernel. The channel could be incorrectly marked idle while descriptors are still active, causing the driver to initiate new transfers prematurely. This leads to descriptor corruption or missed completions, jeopardizing the integrity of data being moved through the DMA engine. The vulnerability’s weakness is a concurrent execution race condition that allows unsafe state changes during interrupt handling.
Affected Systems
All Linux kernel versions that contain the Xilinx DMA driver without the patch referenced in the CVE, including the branches that use the AXIDMA and MCDMA engines. The exact affected releases are not enumerated, but any kernel that incorporates the vulnerable driver before the fix would be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of potential impact, yet the EPSS score of less than 1% implies a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and the typical attack vector would be local privileged access that can queue or manipulate DMA descriptors. Although the exploitability is limited by the need for kernel-space interaction, successful exploitation would result in data corruption or loss of service, making it a significant risk for systems relying on DMA operations.
OpenCVE Enrichment
Debian DLA
Debian DSA