CVE-2026-89941

Source
https://cve.org/CVERecord?id=CVE-2026-89941
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89941.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89941
Downstream
Published
2026-09-16T10:32:29Z
Modified
2026-09-18T03:48:34Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: buffer: Make IIO DMA fence release RCU-safe
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Make IIO DMA fence release RCU-safe

The dma_fence documentation states that if a custom release implementation is provided, the dma_fence object must be freed in an RCU-safe way. The current iio_dma_fence implementation uses kfree(), which might result in a use-after-free.

Remove the custom release implementation. This makes the DMA fence core fall back to dma_fence_free(), which calls kfree_rcu() on the fence. This requires that the fence be the first member of struct iio_dma_fence.

Using the default release method for extended DMA fence structures is a common pattern.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89941.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f
Fixed
311595dc0b5621f74d8eb4dc38ef4efcdfe7e769
Fixed
06a9460b8b792e109cbc934a856d02e5cff217ef
Fixed
11cef99491117d4264603df159c4ff5f3845a059
Fixed
8662e56c31cf23b61ca3d11b516efb94c35b8026

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89941.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89941.json"