CVE-2026-72148

Source
https://cve.org/CVERecord?id=CVE-2026-72148
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72148.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72148
Downstream
Published
2026-08-15T05:53:19Z
Modified
2026-08-25T03:51:31Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H CVSS Calculator
Summary
dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK

The DONE_INT_MASK and ABORT_INT_MASK registers are shared by all DMA channels, and modifying them requires a read-modify-write sequence. Because this operation is not atomic, concurrent calls to dw_edma_v0_core_start() can introduce race conditions if two channels update these registers simultaneously.

Add a spinlock to serialize access to these registers and prevent race conditions.

[den: update dw_edma.lock comment]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72148.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7e4b8a4fbe2cecab0959e862604803d063f50029
Fixed
3989b4775bc2cdbdb4ddc4b1d2420a82b40913f2
Fixed
f60c7463d44fbc1585d247d0bd6976f7a1099472
Fixed
2247cc25a91fb1b5b86586ed55fdd5b725a7477c
Fixed
3ee0f478bb29b4ee892b178179a9a76ddd194149
Fixed
21a9834f56d6249aaa6ca7c2d8c182d66c48c3e1
Fixed
ddbc4a8a4fe296f1fa2e59f7d176fc7c773df640
Fixed
1553ca96e9df158d8f37137cf4bf5fb0dc981d94
Fixed
8ffba0171c6bbce5f093c6dba5a02c0805b31203

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72148.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72148.json"