PT-2026-106672 · Linux · Linux

CVE-2026-98343

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma chan put() and dma release channel()
When dma device put() drops the last reference on chan->device->ref, dma device release() runs and may free the dma device along with its channels.
dma chan put() then still reads chan->device->owner via dma chan to owner() for the trailing module put(). KASAN catches it:
slab-use-after-free in dma chan put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
 kfree+0x225/0x470
 dma chan put+0x395/0x4c0
 dmaengine put+0xf8/0x160
Cache the module owner in dma chan put() before the put so the trailing module put() does not need chan->device.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98343

Affected Products

Linux