CVE-2026-93040

Source
https://cve.org/CVERecord?id=CVE-2026-93040
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93040.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93040
Downstream
Published
2026-09-17T16:10:33Z
Modified
2026-09-19T03:47:26Z
Summary
dmaengine: dw-edma: Serialize channel state checks
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma: Serialize channel state checks

pause() and resume() read and update channel state without holding vc.lock, while the interrupt handlers update the same state under it. Take the same lock around those state checks so that request, status, and configured stay consistent.

For example, pause() can observe EDMA_ST_BUSY right before the interrupt handler completes the final descriptor and moves the channel to EDMA_ST_IDLE, and then record EDMA_REQ_PAUSE on an already idle channel. No further interrupt will acknowledge the request, and since issue_pending() requires EDMA_REQ_NONE, the channel is wedged for good: terminate_all() leaves the stale request behind, so even reconfiguring the channel does not recover it.

issue_pending() already runs under vc.lock, but it tests configured before taking it. Move that test under the lock as well, so configured, request, and status are evaluated as one channel-state snapshot.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93040.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf
Fixed
be0072af8ce6e9458cc586e0e8b41a251e7d4316
Fixed
2d76b91deeab973dd8a8c2ee587ce27f881de768
Fixed
3001cfcee30dcc81f8b3774319c12067f126e49a
Fixed
b6293a8a38f4d5866ce1a264c138265a02e4c53a
Fixed
da16a02f0998a0d455ce6265b836b29ad92e6e58
Fixed
fe0ffa0190e862ed71e8c1a476090f648c9cb7d9
Fixed
6fc436e1500c5e4f0dde2a3dbadf6d898057be8f
Fixed
f7d1619f3e10c619b62c6cd6d95371b5c526c85a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93040.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93040.json"