CVE-2026-89993

Summary

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Initialize IRQ data before requesting IRQs

dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference.

Set the back pointer before installing each handler.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < b86280b12ccf33b68b309b7cb0e4476894dfe77caffected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < 07e50cef557def076418c67051a336e4c6bd50e1affected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < 17ef63843c0fcbf1efdfbbfb0f5584a5ea2c91baaffected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < d232bc6cf4562132ef50644484dfd4b23a593295affected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < fac202d73e7a649b7d4010325c6c6dcd9334fe65affected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < d91fb6c0d10dad32929dc5c6850f89df34e1bfcdaffected
LinuxLinuxe63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf < 647217abea849d3d45f8cb0b8ee5b78d50f26985affected
LinuxLinux5.3affected
LinuxLinux0 < 5.3unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References