CVE-2026-93040: vulnerability in Linux
dmaengine: dw-edma: Serialize channel state checks
Published
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma: Serialize channel state checks
pause() and resume() read and update channel state without holding vc.lock,
while the interrupt handlers update the same state under it. Take the same
lock around those state checks so that request, status, and configured stay
consistent.
For example, pause() can observe EDMA_ST_BUSY right before the interrupt
handler completes the final descriptor and moves the channel to
EDMA_ST_IDLE, and then record EDMA_REQ_PAUSE on an already idle channel. No
further interrupt will acknowledge the request, and since issue_pending()
requires EDMA_REQ_NONE, the channel is wedged for good: terminate_all()
leaves the stale request behind, so even reconfiguring the channel does not
recover it.
issue_pending() already runs under vc.lock, but it tests configured before
taking it. Move that test under the lock as well, so configured, request,
and status are evaluated as one channel-state snapshot.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/2d76b91deeab973dd8a8c2ee587ce27f881de768https://git.kernel.org/stable/c/3001cfcee30dcc81f8b3774319c12067f126e49ahttps://git.kernel.org/stable/c/6fc436e1500c5e4f0dde2a3dbadf6d898057be8fhttps://git.kernel.org/stable/c/b6293a8a38f4d5866ce1a264c138265a02e4c53ahttps://git.kernel.org/stable/c/be0072af8ce6e9458cc586e0e8b41a251e7d4316https://git.kernel.org/stable/c/da16a02f0998a0d455ce6265b836b29ad92e6e58https://git.kernel.org/stable/c/f7d1619f3e10c619b62c6cd6d95371b5c526c85ahttps://git.kernel.org/stable/c/fe0ffa0190e862ed71e8c1a476090f648c9cb7d9