RCU Reader Vulnerability in Linux Kernel dmaengine Component
CVE-2026-98342

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98342?

A race condition vulnerability exists in the Linux kernel's dmaengine component, where concurrent RCU readers may access a dma_device after it has been freed. This vulnerability arises when the device is unlinked from the dma_device_list without ensuring that all RCU readers have completed their operations. The vulnerability was introduced after a modification that decoupled the lifespan of the dma_device from the module reference, allowing for a scenario where readers can access a freed device. To mitigate this, a synchronize_rcu() call has been added prior to the device's release, ensuring that all readers have completed before freeing the associated memory.

Affected Version(s)

Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559

Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559 < 14578c78405d51fa92e4ada4502a45f537c0fcb8

Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.