CVE-2026-72147

Source
https://cve.org/CVERecord?id=CVE-2026-72147
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72147.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72147
Downstream
Published
2026-08-15T05:53:19.170Z
Modified
2026-08-18T03:30:53.043971127Z
Summary
dmaengine: dw-edma-pcie: Reject devices without driver data
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma-pcie: Reject devices without driver data

dwedmapcieprobe() treats the PCI device ID driverdata as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference.

Reject such matches before enabling the device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72147.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569
Fixed
2733b5dcb5a4ba4446f7bac954b97e4501dcaa64
Fixed
a1042599fa8f9e313be176eb1ea1ae199f983419
Fixed
043acb00e4edd4b9ffb9dd0e357482dcd9086486
Fixed
044f7b3252d4fb2143d4999eec2800c08f1001ed
Fixed
11d7cfe0c119691b2dafbb699bbca90258c678aa

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72147.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72147.json"