7.8

CVE-2026-89940

iio: buffer: Tie IIO dma fence lock lifetime to the fence

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Tie IIO dma fence lock lifetime to the fence

The `iio_dma_fence` implementation currently uses a lock embedded in the
`iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the
`iio_dmabuf_priv`, which can cause a use-after-free.

Tie the lifetime of the lock to the lifetime of the fence by embedding them
in the same struct.

We can't just hold a reference to the `iio_dmabuf_priv` from the
`iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the
fence release callback is not allowed to sleep.

Note that the `dma_fence` framework now has an internal lock that gets used
when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to
allow this patch to be backportable use an external lock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Version < 6865d79fca17a80fbd60c12550ca9a5e0e20e0eb
Status affected
Version 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Version < 510497e31be4f241103507315a859e2085ccb081
Status affected
Version 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Version < 8b3e221590181a8beb3735bbabf166df02c839b5
Status affected
Version 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Version < f25ec4627d935dedfb5fe83bd2c2678cdcc19611
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6865d79fca17a80fbd60c12550ca9a5e0e20e0eb
https://git.kernel.org/stable/c/510497e31be4f241103507315a859e2085ccb081
https://git.kernel.org/stable/c/8b3e221590181a8beb3735bbabf166df02c839b5
https://git.kernel.org/stable/c/f25ec4627d935dedfb5fe83bd2c2678cdcc19611