Executive brief
A memory management issue was identified in the Linux kernel's DMA (Direct Memory Access) subsystem. Specifically, the system fails to properly release certain internal data structures when a hardware routing request fails. Over time, this could lead to a memory leak that degrades system performance or causes a crash, potentially allowing a local user to disrupt system operations.
Technical details
A reference count leak exists in drivers/dma/dw/rzn1-dmamux.c within the rzn1_dmamux_route_allocate function. When a late route allocation failure occurs (e.g., when a request index is already in use), the code fails to call of_node_put() on the DMA master OF node. This results in a persistent memory leak of the node reference. An attacker with local access could potentially trigger this failure repeatedly to exhaust system memory resources. The issue has been resolved by adding the missing of_node_put() call in the error handling path.
Affected products
- Linux Linux Kernel 5.19 to 6.1.162, 6.2 to 6.6.122, 6.7 to 6.12.67, 6.13 to 6.18.7
Timeline
- 2025-11-17: other: Patch authored
- 2026-01-31: disclosed: CVE published
- 2026-02-06: patched: Patch committed to stable tree
References
- https://git.kernel.org/stable/c/6b87288581a0fcbe54b39da5c10e1aee2df8776e
- https://git.kernel.org/stable/c/8f7a391211381ed2f6802032c78c7820d166bc49
- https://git.kernel.org/stable/c/db7c79c1bbfb1b0184e78a17ac2bd0f2bc3134d1
- https://git.kernel.org/stable/c/eabe40f8a53c29f531e92778ea243e379f4f7978
- https://git.kernel.org/stable/c/ec25e60f9f95464aa11411db31d0906b3fb7b9f2
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html