CVE-2026-93040: fallo en Linux
dmaengine: dw-edma: Serialize channel state checks
Publicada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma: Serialize channel state checks
pause() and resume() read and update channel state without holding vc.lock,
while the interrupt handlers update the same state under it. Take the same
lock around those state checks so that request, status, and configured stay
consistent.
For example, pause() can observe EDMA_ST_BUSY right before the interrupt
handler completes the final descriptor and moves the channel to
EDMA_ST_IDLE, and then record EDMA_REQ_PAUSE on an already idle channel. No
further interrupt will acknowledge the request, and since issue_pending()
requires EDMA_REQ_NONE, the channel is wedged for good: terminate_all()
leaves the stale request behind, so even reconfiguring the channel does not
recover it.
issue_pending() already runs under vc.lock, but it tests configured before
taking it. Move that test under the lock as well, so configured, request,
and status are evaluated as one channel-state snapshot.
Productos afectados
Linux · LinuxCVEs relacionadas — Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referencias
https://git.kernel.org/stable/c/2d76b91deeab973dd8a8c2ee587ce27f881de768https://git.kernel.org/stable/c/3001cfcee30dcc81f8b3774319c12067f126e49ahttps://git.kernel.org/stable/c/6fc436e1500c5e4f0dde2a3dbadf6d898057be8fhttps://git.kernel.org/stable/c/b6293a8a38f4d5866ce1a264c138265a02e4c53ahttps://git.kernel.org/stable/c/be0072af8ce6e9458cc586e0e8b41a251e7d4316https://git.kernel.org/stable/c/da16a02f0998a0d455ce6265b836b29ad92e6e58https://git.kernel.org/stable/c/f7d1619f3e10c619b62c6cd6d95371b5c526c85ahttps://git.kernel.org/stable/c/fe0ffa0190e862ed71e8c1a476090f648c9cb7d9