CVE-2026-98343

Source
https://cve.org/CVERecord?id=CVE-2026-98343
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98343.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98343
Downstream
Published
2026-10-06T08:46:33Z
Modified
2026-10-08T02:52:57Z
Summary
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
Details

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()

When dma_device_put() drops the last reference on chan->device->ref, dma_device_release() runs and may free the dma_device along with its channels.

dma_chan_put() then still reads chan->device->owner via dma_chan_to_owner() for the trailing module_put(). KASAN catches it:

slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
  kfree+0x225/0x470
  dma_chan_put+0x395/0x4c0
  dmaengine_put+0xf8/0x160

Cache the module owner in dma_chan_put() before the put so the trailing module_put() does not need chan->device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98343.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8ad342a863590b24ce77681b7e081363fb3333f7
Fixed
b92c502595336a3cc5bb7a060170891366745a5d
Fixed
855187a88bdf762c46b6849307597e3e02bfc1d9
Fixed
c9780b601438137494b407eb4301bb3de2587ac9
Fixed
07eb075b60d565a5e465a1945a80cc62807492ad
Fixed
9319dd64d5cdef851841c091f30424faa2284c31
Fixed
6cf31716b77a71c0d634106f4f3951377b8dc6dc
Fixed
02bd02c585293634b213b142cba63cbf77891f6b
Fixed
e873c74132f0c5f1452816cd9bb26208f0bba1e1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98343.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98343.json"