CVE-2026-98343: falha em Linux
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
Publicada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://git.kernel.org/stable/c/02bd02c585293634b213b142cba63cbf77891f6bhttps://git.kernel.org/stable/c/07eb075b60d565a5e465a1945a80cc62807492adhttps://git.kernel.org/stable/c/6cf31716b77a71c0d634106f4f3951377b8dc6dchttps://git.kernel.org/stable/c/855187a88bdf762c46b6849307597e3e02bfc1d9https://git.kernel.org/stable/c/9319dd64d5cdef851841c091f30424faa2284c31https://git.kernel.org/stable/c/b92c502595336a3cc5bb7a060170891366745a5dhttps://git.kernel.org/stable/c/c9780b601438137494b407eb4301bb3de2587ac9https://git.kernel.org/stable/c/e873c74132f0c5f1452816cd9bb26208f0bba1e1