AZL-106251

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106251.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106251
Upstream
Published
2026-10-06T09:18:27Z
Modified
2026-10-07T14:17:00Z
Summary
CVE-2026-98344 affecting package kernel 6.6.157.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: Fix device kref underflow in dma_chan_put()

dma_chan_get() takes chan->device->ref only on the slow path:

/* no kref on fast path */
if (chan->client_count) {
	__module_get(owner);
	chan->client_count++;
	return 0;
}
if (!try_module_get(owner))
	return -ENODEV;
if (!dma_device_get(chan->device)) { // calls kref_get_unless_zero()

dma_chan_put() drops the ref unconditionally, so every fast-path get/put pair drops one extra device reference.

The bug fires when two conditions hold together: a non-private provider has a persistent client holding chan->client_count > 0 and another client cycles dmaengine_get()/dmaengine_put(). When the kref hits zero, the subsequent dma_find_channel() returns NULL even though the provider module is still loaded.

Fix this by dropping device->ref only on the last put, matching the single slow-path get.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.6.157.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106251.json"