UNKNOWN NVD
CVE-2026-98343
In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() When dma_device_
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
References
- https://git.kernel.org/stable/c/02bd02c585293634b213b142cba63cbf77891f6b
- https://git.kernel.org/stable/c/07eb075b60d565a5e465a1945a80cc62807492ad
- https://git.kernel.org/stable/c/6cf31716b77a71c0d634106f4f3951377b8dc6dc
- https://git.kernel.org/stable/c/855187a88bdf762c46b6849307597e3e02bfc1d9
- https://git.kernel.org/stable/c/9319dd64d5cdef851841c091f30424faa2284c31
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.