CVE-2026-89940

Source
https://cve.org/CVERecord?id=CVE-2026-89940
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89940.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89940
Downstream
Published
2026-09-16T10:32:28Z
Modified
2026-09-18T03:46:28Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: buffer: Tie IIO dma fence lock lifetime to the fence
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Tie IIO dma fence lock lifetime to the fence

The iio_dma_fence implementation currently uses a lock embedded in the iio_dmabuf_priv. But the iio_dma_fence can outlive the iio_dmabuf_priv, which can cause a use-after-free.

Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct.

We can't just hold a reference to the iio_dmabuf_priv from the iio_dma_fence since iio_buffer_dmabuf_release() might sleep and the fence release callback is not allowed to sleep.

Note that the dma_fence framework now has an internal lock that gets used when the passing NULL for lock in dma_fence_init(), but in order to allow this patch to be backportable use an external lock.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89940.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Fixed
6865d79fca17a80fbd60c12550ca9a5e0e20e0eb
Fixed
510497e31be4f241103507315a859e2085ccb081
Fixed
8b3e221590181a8beb3735bbabf166df02c839b5
Fixed
f25ec4627d935dedfb5fe83bd2c2678cdcc19611

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89940.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89940.json"