CVE-2026-80902

Summary

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA

When terminating DMA transfers, active descriptors are not properly reclaimed. Only cyclic descriptors were handled, leaving non-cyclic descriptors and their LLI chains to be permanently leaked.

Fix by using vchan_terminate_vdesc() which handles both cyclic and non-cyclic descriptors by adding them to desc_terminated queue for proper cleanup.

Add pchan->desc != pchan->done check to prevent double-adding completed descriptors, which would corrupt the list.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < bb87440561eb72b47a2b848b5373b86433b247e6affected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < 004a7a02982bed0a727a4ac7be400f00f353e7a2affected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < b150f603083cc8b72b0cbf13ec3e91f85b4390a0affected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < 27806fe7b9701af0963dcd510e30e7d0cc314c43affected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < 1ccc5c059d067c5358682ad5352e7d7e9239ed9baffected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < 9086b488f2737d5dcee86852b83f2059f1cdfabfaffected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < d4ba6aa65fcd797152d3aebd428a7b2da49cd5ebaffected
LinuxLinux555859308723d8d5b828304f5eb9281143fd86b5 < ab1150115e68a46b687eb38c1ab92782018c9f2caffected
LinuxLinux3.17affected
LinuxLinux0 < 3.17unaffected
LinuxLinux5.10.265 <= 5.10.*unaffected
LinuxLinux5.15.216 <= 5.15.*unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.151 <= 6.6.*unaffected
LinuxLinux6.12.103 <= 6.12.*unaffected
LinuxLinux6.18.44 <= 6.18.*unaffected
LinuxLinux7.1.8 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References