« Volver al listado

CVE-2026-93168

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout

Currently when calling xilinx_dma_poll_timeout with delay_us=0 and a condition that is never fulfilled, the CPU busy-waits for prolonged time and the timeout triggers only with a massive delay causing a CPU stall.

This happens due to a huge underestimation of wall clock time in poll_timeout_us_atomic. Commit 7349a69cf312 ("iopoll: Do not use timekeeping in read_poll_timeout_atomic()") changed the behavior to no longer use ktime_get at the expense of underestimation of wall clock time which appears to be very large for delay_us=0. Instead of timing out after approximately XILINX_DMA_LOOP_COUNT microseconds, the timeout takes XILINX_DMA_LOOP_COUNT * 1000 * (time that the overhead of the for loop in poll_timeout_us_atomic takes) which is in the range of several minutes for XILINX_DMA_LOOP_COUNT=1000000. Fix this by using a non-zero value for delay_us. Use delay_us=10 to keep the delay in the hot path of starting DMA transfers minimal but still avoid CPU stalls in case of unexpected hardware failures.

Leer descripción completaMostrar menos

One-off measurement with delay_us=0 causes the cpu to busy wait around 7 minutes in the timeout case. After applying this patch with delay_us=10 the measured timeout was 1053428 microseconds which is roughly equivalent to the expected 1000000 microseconds specified in XILINX_DMA_LOOP_COUNT.

Add a constant XILINX_DMA_POLL_DELAY_US for delay_us value.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93168",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9495f2648287029fb5545c34a0fa318426ebe84c",
              "lessThan": "8b5654d317277e6e505c23f8fa7e415237fefc7f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9495f2648287029fb5545c34a0fa318426ebe84c",
              "lessThan": "aa99c4d1d63bbc26a5fc4c667d89b2595743c19d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/dma/xilinx/xilinx_dma.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/dma/xilinx/xilinx_dma.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:12.403",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/8b5654d317277e6e505c23f8fa7e415237fefc7f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa99c4d1d63bbc26a5fc4c667d89b2595743c19d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout\n\nCurrently when calling xilinx_dma_poll_timeout with delay_us=0 and a\ncondition that is never fulfilled, the CPU busy-waits for prolonged time\nand the timeout triggers only with a massive delay causing a CPU stall.\n\nThis happens due to a huge underestimation of wall clock time in\npoll_timeout_us_atomic. Commit 7349a69cf312 (\"iopoll: Do not use\ntimekeeping in read_poll_timeout_atomic()\") changed the behavior to no\nlonger use ktime_get at the expense of underestimation of wall clock\ntime which appears to be very large for delay_us=0. Instead of timing\nout after approximately XILINX_DMA_LOOP_COUNT microseconds, the timeout\ntakes XILINX_DMA_LOOP_COUNT * 1000 * (time that the overhead of the for\nloop in poll_timeout_us_atomic takes) which is in the range of several\nminutes for XILINX_DMA_LOOP_COUNT=1000000. Fix this by using a non-zero\nvalue for delay_us. Use delay_us=10 to keep the delay in the hot path of\nstarting DMA transfers minimal but still avoid CPU stalls in case of\nunexpected hardware failures.\n\nOne-off measurement with delay_us=0 causes the cpu to busy wait around 7\nminutes in the timeout case. After applying this patch with delay_us=10\nthe measured timeout was 1053428 microseconds which is roughly\nequivalent to the expected 1000000 microseconds specified in\nXILINX_DMA_LOOP_COUNT.\n\nAdd a constant XILINX_DMA_POLL_DELAY_US for delay_us value."
    }
  ],
  "lastModified": "2026-09-17T17:18:12.403",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}