CVE-2026-93042
CVE CVE-2026-93042EUVD EUVD-2026-82152Published 2026-09-17T16:10:34.000ZLast changed 2026-09-18T17:55:44.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without callbacks The DMA Engine client documentation says in the "Terminate APIs" section of Documentation/driver-api/dmaengine/client.rst: "No callback functions will be called for any incomplete transfers." dw-edma instead calls vchan_cookie_complete() when a deferred STOP reaches the interrupt handler. This schedules a callback for the active descriptor and leaves other issued or submitted descriptors queued. A late callback after dmaengine_terminate_sync() can dereference client state that has already been freed, while leftover descriptors may later restart into reused buffers or leak. Move all issued and submitted descriptors to the terminated list whenever termination completes. For a pending STOP, do this from both the DONE and ABORT paths. Complete their cookies in order without scheduling callbacks. A STOP can remain pending until the running transfer raises an interrupt. Make device_synchronize() wait for such a pending STOP to complete before releasing terminated descriptors. Reuse it from free_chan_resources(), then release the remaining virt-dma resources. Sleep instead of busy-polling while waiting, and warn if the existing timeout expires.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5.3; e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf <65e387b95d3855aa894ac729e1778e5bcb9083cb; patch: 7.2.6; e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf <99109a51efd28c9a661fbfb9469b023c517b31d1; e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf <be87d86537de7ea6fd025f41033d2faff880973f; patch: 6.6.157; patch: 6.18.52; patch: 0; e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf <f3ec6702a1d216be61f692cc0a983d6c8fb5ebf7; patch: 6.12.110; patch: 7.3-rc1; e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf <4793f9099a1cadf4e37f3a03d524af6bce88a0ea
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.