PT-2026-106672 · Linux · Linux
CVE-2026-98343
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma chan put() and dma release channel()
When dma device put() drops the last reference on chan->device->ref,
dma device release() runs and may free the dma device along with its
channels.
dma chan put() then still reads chan->device->owner via
dma chan to owner() for the trailing module put(). KASAN catches it:
slab-use-after-free in dma chan put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma chan put+0x395/0x4c0
dmaengine put+0xf8/0x160Cache the module owner in dma chan put() before the put so the trailing
module put() does not need chan->device.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux