Use-After-Free Vulnerability in Linux Kernel Affects DMA Channel Management
CVE-2026-98343

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98343?

A use-after-free vulnerability has been identified in the Linux kernel during the management of DMA channels. An issue occurs when the last reference to a DMA device is dropped, leading to potential access violations. Specifically, after the dma_device_put() function releases the device reference, the dma_chan_put() function attempts to access the freed memory, resulting in undefined behavior. This flaw can be exploited in process management and leads to risks such as arbitrary code execution or system instability. The vulnerability has been addressed by caching the module owner before the reference is released, preventing access to freed memory.

Affected Version(s)

Linux 8ad342a863590b24ce77681b7e081363fb3333f7

Linux 8ad342a863590b24ce77681b7e081363fb3333f7 < 855187a88bdf762c46b6849307597e3e02bfc1d9

Linux 8ad342a863590b24ce77681b7e081363fb3333f7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.