DMA Termination Vulnerability in Linux Kernel Affects Multiple Versions
CVE-2026-80902

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80902?

A vulnerability in the Linux kernel's DMA engine has been identified, where active descriptors are not adequately reclaimed during the termination of DMA transfers. This oversight primarily affects non-cyclic descriptors and their associated LLI chains, leading to potential memory leaks. The issue has been addressed by implementing a fix that uses the vchan_terminate_vdesc() function, enhancing the cleanup process to account for both cyclic and non-cyclic descriptors. Additionally, the check to prevent double-adding completed descriptors has been introduced to maintain list integrity.

Affected Version(s)

Linux 555859308723d8d5b828304f5eb9281143fd86b5

Linux 555859308723d8d5b828304f5eb9281143fd86b5 < 004a7a02982bed0a727a4ac7be400f00f353e7a2

Linux 555859308723d8d5b828304f5eb9281143fd86b5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.