Executive brief
The Xilinx ZynqMP DMA controller driver in the Linux kernel had a race condition during device removal that could occur when runtime power management and device unbinding happen concurrently. This race could cause improper device state transitions, potentially leading to system instability or resource leaks when DMA devices are hot-removed or the driver module is unloaded.
Technical details
This is a race condition in the zynqmp_dma driver's remove() function (drivers/dma/xilinx/zynqmp_dma.c). The vulnerable code checked if runtime PM was active and manually suspended the device before disabling runtime PM. This sequence allowed a concurrent runtime PM transition to occur between the state check and PM disable, causing inconsistent device state. The fix reorders the operations: runtime PM is disabled first (preventing further transitions), then the device is suspended only if not already suspended. This is a concurrency/synchronization bug (CWE-366) affecting kernel drivers, not a remote vulnerability. Local access is required to trigger device removal/unbind.
Affected products
- Linux Linux kernel Multiple kernel versions (2.6.11 through 7.2, rolling-lts, rolling-stable)
Timeline
- 2026-09-17: disclosed
- 2026-06-30: patched