Executive brief
The Linux kernel's Tegra GPC DMA driver has a flaw in calculating burst sizes for data transfers that causes the DMA hardware to hang when transfer lengths are not evenly divisible by the configured burst size. This can freeze UART and other peripheral operations that rely on DMA, leading to system communication delays or failures.
Technical details
The vulnerability is a logic error in the get_burst_size() function of the Tegra186 GPC DMA driver (drivers/dma/tegra186-gpc-dma.c). The Tegra GPC DMA hardware requires the transfer length to be a multiple of the burst size; when a transfer length is not evenly divisible by the configured max burst size, partial bursts occur at the end and the hardware hangs. The fix reduces the burst size to the largest power-of-2 value that evenly divides the transfer length, ensuring complete bursts only. No authentication is required; the issue affects any kernel subsystem or driver using Tegra GPC DMA with arbitrary-length transfers (notably the PL011 UART TX driver). The patch is available in Linux kernel stable branches.
Affected products
- Linux Linux kernel affected versions include linux-4.x through linux-7.x and related stable branches
Timeline
- 2026-08-15: disclosed
- 2026-06-08: patched: fix committed upstream; backported to stable branches