DMA Termination Vulnerability in Linux Kernel Affects Multiple Versions
CVE-2026-80902
What is CVE-2026-80902?
A vulnerability in the Linux kernel's DMA engine has been identified, where active descriptors are not adequately reclaimed during the termination of DMA transfers. This oversight primarily affects non-cyclic descriptors and their associated LLI chains, leading to potential memory leaks. The issue has been addressed by implementing a fix that uses the vchan_terminate_vdesc() function, enhancing the cleanup process to account for both cyclic and non-cyclic descriptors. Additionally, the check to prevent double-adding completed descriptors has been introduced to maintain list integrity.
Affected Version(s)
Linux 555859308723d8d5b828304f5eb9281143fd86b5
Linux 555859308723d8d5b828304f5eb9281143fd86b5 < 004a7a02982bed0a727a4ac7be400f00f353e7a2
Linux 555859308723d8d5b828304f5eb9281143fd86b5