CVE-2026-89940
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: buffer: Tie IIO dma fence lock lifetime to the fence
The iio_dma_fence implementation currently uses a lock embedded in the
iio_dmabuf_priv. But the iio_dma_fence can outlive the
iio_dmabuf_priv, which can cause a use-after-free.
Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct.
We can't just hold a reference to the iio_dmabuf_priv from the
iio_dma_fence since iio_buffer_dmabuf_release() might sleep and the
fence release callback is not allowed to sleep.
Note that the dma_fence framework now has an internal lock that gets used
when the passing NULL for lock in dma_fence_init(), but in order to
allow this patch to be backportable use an external lock.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 6865d79fca17a80fbd60c12550ca9a5e0e20e0eb | affected |
| Linux | Linux | 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 510497e31be4f241103507315a859e2085ccb081 | affected |
| Linux | Linux | 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 8b3e221590181a8beb3735bbabf166df02c839b5 | affected |
| Linux | Linux | 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < f25ec4627d935dedfb5fe83bd2c2678cdcc19611 | affected |
| Linux | Linux | 6.11 | affected |
| Linux | Linux | 0 < 6.11 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/6865d79fca17a80fbd60c12550ca9a5e0e20e0eb
- https://git.kernel.org/stable/c/510497e31be4f241103507315a859e2085ccb081
- https://git.kernel.org/stable/c/8b3e221590181a8beb3735bbabf166df02c839b5
- https://git.kernel.org/stable/c/f25ec4627d935dedfb5fe83bd2c2678cdcc19611
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.