CVE-2026-98343
Received
Received - Intake
Use-After-Free in Linux Kernel DMA Engine
Vulnerability report for CVE-2026-98343, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 8ad342a863590b24ce77681b7e081363fb3333f7 |
| Linux | Linux | 5.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |