RCU Reader Vulnerability in Linux Kernel dmaengine Component
CVE-2026-98342
What is CVE-2026-98342?
A race condition vulnerability exists in the Linux kernel's dmaengine component, where concurrent RCU readers may access a dma_device after it has been freed. This vulnerability arises when the device is unlinked from the dma_device_list without ensuring that all RCU readers have completed their operations. The vulnerability was introduced after a modification that decoupled the lifespan of the dma_device from the module reference, allowing for a scenario where readers can access a freed device. To mitigate this, a synchronize_rcu() call has been added prior to the device's release, ensuring that all readers have completed before freeing the associated memory.
Affected Version(s)
Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559
Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559 < 14578c78405d51fa92e4ada4502a45f537c0fcb8
Linux 2ba05622b8b143b0c95968ba59bddfbd6d2f2559