PT-2026-106671 · Linux · Linux
CVE-2026-98342
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: wait for RCU readers before releasing dma device
dma issue pending all() walks the dma device list with
list for each entry rcu() under rcu read lock(). dma device release()
unlinks the device with list del rcu() and then calls
device->device release() (which in many drivers, such as plx dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma issue pending all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma device struct") decoupled the dma device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device release() free the device themselves once
dma async device unregister() returns. This call will delay for a grace
period with dma list mutex held, which is safe and only teardown path is
delayed.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux