Executive brief
A vulnerability was identified in the Linux kernel's data movement engine (dmaengine) specifically affecting Intel's Data Streaming Accelerator (IDXD) driver. This component is responsible for high-performance data transfers and cryptographic acceleration. An exploit could lead to system instability, data corruption, or a complete system crash, potentially impacting business operations and service availability.
Technical details
A logic error exists in the 'llist_abort_desc()' function within the 'drivers/dma/idxd/submit.c' component of the Linux kernel. During the abort process, the code incorrectly references a static 'found' descriptor instead of the current traversal cursor 'd' during a list loop. This mismatch can result in NULL pointer dereferences, double completion of descriptors, or descriptor leaks. An attacker could potentially leverage this to cause a Denial of Service (DoS) or achieve arbitrary code execution. Patches have been released for multiple stable kernel branches including 6.12.y, 6.18.y, and 6.19.y.
Affected products
- Linux Linux Kernel 6.8 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc6
Timeline
- 2026-01-06: other: Vulnerability reported/fixed in upstream code
- 2026-04-22: disclosed: Initial publication date
- 2026-04-22: advisory: Advisory published by kernel.org
- 2026-05-19: other: NVD analysis and CPE enrichment