« Volver al listado

CVE-2026-98343

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()

When dma_device_put() drops the last reference on chan->device->ref, dma_device_release() runs and may free the dma_device along with its channels.

dma_chan_put() then still reads chan->device->owner via dma_chan_to_owner() for the trailing module_put(). KASAN catches it:

Cache the module owner in dma_chan_put() before the put so the trailing module_put() does not need chan->device.

Detalles técnicos trazas, registros y código del informe original
	slab-use-after-free in dma_chan_put+0x3e6/0x4c0
	Read of size 8 by task insmod/6319
	Freed by task 6319:
	  kfree+0x225/0x470
	  dma_chan_put+0x395/0x4c0
	  dmaengine_put+0xf8/0x160

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98343",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "b92c502595336a3cc5bb7a060170891366745a5d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "855187a88bdf762c46b6849307597e3e02bfc1d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "c9780b601438137494b407eb4301bb3de2587ac9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "07eb075b60d565a5e465a1945a80cc62807492ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "9319dd64d5cdef851841c091f30424faa2284c31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "6cf31716b77a71c0d634106f4f3951377b8dc6dc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "02bd02c585293634b213b142cba63cbf77891f6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ad342a863590b24ce77681b7e081363fb3333f7",
              "lessThan": "e873c74132f0c5f1452816cd9bb26208f0bba1e1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/dma/dmaengine.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/dma/dmaengine.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:27.163",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/02bd02c585293634b213b142cba63cbf77891f6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/07eb075b60d565a5e465a1945a80cc62807492ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6cf31716b77a71c0d634106f4f3951377b8dc6dc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/855187a88bdf762c46b6849307597e3e02bfc1d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9319dd64d5cdef851841c091f30424faa2284c31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b92c502595336a3cc5bb7a060170891366745a5d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9780b601438137494b407eb4301bb3de2587ac9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e873c74132f0c5f1452816cd9bb26208f0bba1e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()\n\nWhen dma_device_put() drops the last reference on chan->device->ref,\ndma_device_release() runs and may free the dma_device along with its\nchannels.\n\ndma_chan_put() then still reads chan->device->owner via\ndma_chan_to_owner() for the trailing module_put(). KASAN catches it:\n\n\tslab-use-after-free in dma_chan_put+0x3e6/0x4c0\n\tRead of size 8 by task insmod/6319\n\tFreed by task 6319:\n\t  kfree+0x225/0x470\n\t  dma_chan_put+0x395/0x4c0\n\t  dmaengine_put+0xf8/0x160\n\nCache the module owner in dma_chan_put() before the put so the trailing\nmodule_put() does not need chan->device."
    }
  ],
  "lastModified": "2026-10-06T09:18:27.163",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}