PT-2026-106671 · Linux · Linux
CVE-2026-98342
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: wait for RCU readers before releasing dma device
dma issue pending all() walks the dma device list with
list for each entry rcu() under rcu read lock(). dma device release()
unlinks the device with list del rcu() and then calls
device->device release() (which in many drivers, such as plx dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma issue pending all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma device struct") decoupled the dma device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device release() free the device themselves once
dma async device unregister() returns. This call will delay for a grace
period with dma list mutex held, which is safe and only teardown path is
delayed.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux