Device Reference Count Underflow in Linux Kernel Affects DMA Channel Management
CVE-2026-98344
What is CVE-2026-98344?
A vulnerability in the Linux kernel's DMA engine has been identified, leading to a device reference count underflow. This issue arises during the management of DMA channels, specifically when the dma_chan_put() function drops the device reference unconditionally. If certain conditions are met, including the presence of a persistent client and another client cycling through dmaengine_get() and dmaengine_put(), it can lead to a situation where a valid provider module is unloaded prematurely, ultimately returning NULL from dma_find_channel(). The fix ensures that the device reference is only dropped during the last put operation, aligning it with the respective slow-path gets, thereby maintaining proper reference counting integrity.
Affected Version(s)
Linux 8ad342a863590b24ce77681b7e081363fb3333f7 < 036b527f92570206da4b8c40b38f8d689e29d0f3
Linux 8ad342a863590b24ce77681b7e081363fb3333f7 < 5fb1797a8c9485e40e5492fa0338ab5c7d1f3fef
Linux 8ad342a863590b24ce77681b7e081363fb3333f7 < 57f7f1c6827be7d8f80feca48d2125fb91c6f6ed