CVE-2026-93169

Summary

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: zynqmp_dma: fix race between runtime PM and device removal

In zynqmp_dma_remove(), runtime PM was disabled only after checking state and doing a manual suspend. This can race with runtime PM in the remove/unbind (rmmod) path.

Disable runtime PM first, then suspend only if the device is not already suspended. To prevent any further runtime PM transitions.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux72dd8b2914b5db1dccf902971c2ea6b541711b28 < 32f69e6c95b59f9cfc649ebf352a204d23ba93d7affected
LinuxLinux72dd8b2914b5db1dccf902971c2ea6b541711b28 < aec7cf9a5bd89047c58d5648bfce0b1bd19ba7d5affected
LinuxLinux72dd8b2914b5db1dccf902971c2ea6b541711b28 < 516ba2d8b7aac4238f9fcbd58579c43c71b9b695affected
LinuxLinux6.18affected
LinuxLinux0 < 6.18unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References