Junglewise Threat Intelligence

CVE-2026-93040: Linux kernel dw-edma race condition in channel state management

CVE-2026-93040 · Severity: info · CVSS 0 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Synopsys eDMA driver has a race condition in how it manages DMA channel state across pause, resume, and interrupt handlers. If pause() is called at precisely the wrong moment, a channel can become permanently stuck ("wedged"), unable to process new data transfers even after reconfiguration. This could cause DMA operations to silently fail, disrupting I/O performance on systems using this driver.

Technical details

The vulnerability is a race condition (CWE-362) in the dw-edma DMA engine driver's channel state management. The pause() and resume() functions read and modify channel state variables (configured, status, request) without holding the vc.lock spinlock, while interrupt handlers update the same state under the lock. This allows pause() to observe EDMA_ST_BUSY and record EDMA_REQ_PAUSE on a channel that simultaneously transitions to EDMA_ST_IDLE via interrupt, leaving a stale pause request that no interrupt will acknowledge. Since issue_pending() requires EDMA_REQ_NONE, the channel becomes permanently unusable. The fix adds spinlock protection around state checks in pause() and resume(), and moves the configured check in issue_pending() under the lock to ensure atomic snapshot of channel state.

Affected products

  • Linux Linux kernel Affected versions not explicitly specified in advisory; patch applies to multiple stable branches from linux-4.4.y onwards

Timeline

  • 2026-09-17: disclosed
  • 2026-09-14: patched: Patch commit f7d1619f3e10c619b62c6cd6d95371b5c526c85a merged to stable branches

References

Related threats