CVE-2026-89941

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Make IIO DMA fence release RCU-safe

The dma_fence documentation states that if a custom release implementation is provided, the dma_fence object must be freed in an RCU-safe way. The current iio_dma_fence implementation uses kfree(), which might result in a use-after-free.

Remove the custom release implementation. This makes the DMA fence core fall back to dma_fence_free(), which calls kfree_rcu() on the fence. This requires that the fence be the first member of struct iio_dma_fence.

Using the default release method for extended DMA fence structures is a common pattern.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 311595dc0b5621f74d8eb4dc38ef4efcdfe7e769affected
LinuxLinux3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 06a9460b8b792e109cbc934a856d02e5cff217efaffected
LinuxLinux3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 11cef99491117d4264603df159c4ff5f3845a059affected
LinuxLinux3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f < 8662e56c31cf23b61ca3d11b516efb94c35b8026affected
LinuxLinux6.11affected
LinuxLinux0 < 6.11unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References