Junglewise Threat Intelligence

CVE-2026-80698: Linux kernel dmaengine idxd double free in device cleanup

CVE-2026-80698 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Intel Data Accelerators (IDXD) DMA engine driver contained a double-free memory safety bug in its device cleanup routines. When work queue, engine, or group devices were torn down, the kernel could free the same memory region twice, potentially leading to kernel crashes or memory corruption during system shutdown or device removal.

Technical details

This is a use-after-free / double-free vulnerability in the dmaengine idxd driver (drivers/dma/idxd/init.c). The root cause stems from conflicting ownership of device struct memory: release callbacks (idxd_conf_wq_release, idxd_conf_engine_release, idxd_conf_group_release) call kfree() on their enclosing structs, but error paths in setup functions and cleanup routines also call kfree() explicitly after put_device(). Since device_initialize() is called before device_add(), the reference count is exactly 1 at error sites, so put_device() unconditionally triggers the release callback and frees memory; the subsequent explicit kfree() then operates on freed memory. The vulnerability is triggered during device setup failure or normal cleanup when put_device() is called. No network attack vector; exploitation requires local access (e.g., device removal or driver unload). A patch was released removing redundant kfree() calls and delegating sole ownership to release callbacks.

Affected products

  • Linux Linux Kernel multiple versions (see git commits fixing earlier versions dating back several years)

Timeline

  • 2026-04-15: other: Fix commit authored by Yuho Choi
  • 2026-07-02: patched: Fix merged into mainline by Vinod Koul
  • 2026-08-28: disclosed: CVE-2026-80698 published

References

Related threats