PT-2026-93581 · Linux · Linux Kernel

CVE-2026-89940

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the iio dma fence implementation. The problem occurs because the implementation uses a lock embedded in iio dmabuf priv, but the iio dma fence can outlive the iio dmabuf priv structure. This is further complicated by the fact that iio buffer dmabuf release() might sleep, while the fence release callback is not permitted to sleep, preventing the use of a simple reference to iio dmabuf priv from iio dma fence.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89940
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel