Executive brief
The Linux kernel's dw-edma DMA controller driver improperly handles termination of DMA transfers. When a client application stops a DMA operation, the driver may still call completion callbacks after the client has freed its resources, leading to use-after-free crashes. Additionally, incomplete DMA descriptors may be restarted into recycled memory buffers, causing data corruption or information leaks.
Technical details
The vulnerability is a use-after-free and data-structure handling defect in the dw-edma driver's DMA termination code (drivers/dma/dw-edma/dw-edma-core.c). The root cause is that dw-edma calls vchan_cookie_complete() when a deferred STOP interrupt is processed, which schedules callbacks for active descriptors while leaving other issued or submitted descriptors queued. This violates the DMA Engine client contract that states "No callback functions will be called for any incomplete transfers." An attacker with ability to trigger DMA termination followed by buffer reuse can cause a late callback to dereference freed kernel memory or allow leftover descriptors to restart into reused buffers. The fix moves all incomplete descriptors to a terminated list without scheduling callbacks, synchronizes pending STOP operations, and properly completes cookies in order. Network exposure is limited to systems using this specific eDMA controller, requiring local DMA access or a malicious driver/application.
Affected products
- Linux Linux Kernel 4.0 and later (vulnerable dw-edma driver present in multiple versions)
Timeline
- 2026-09-17: disclosed
- 2026-09-14: advisory: Advisory published by kernel maintainers
- 2026-09-14: patched: Fix committed to stable kernel tree