CVE-2026-89941

Published: Set 16, 2026 Last Modified: Set 16, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,8
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Make IIO DMA fence release RCU-safe

The `dma_fence` documentation states that if a custom release
implementation is provided, the `dma_fence` object must be freed in an
RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`,
which might result in a use-after-free.

Remove the custom `release` implementation. This makes the DMA fence core
fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence.
This requires that the fence be the first member of `struct iio_dma_fence`.

Using the default release method for extended DMA fence structures is a
common pattern.

https://git.kernel.org/stable/c/06a9460b8b792e109cbc934a856d02e5cff217ef
https://git.kernel.org/stable/c/11cef99491117d4264603df159c4ff5f3845a059
https://git.kernel.org/stable/c/311595dc0b5621f74d8eb4dc38ef4efcdfe7e769
https://git.kernel.org/stable/c/8662e56c31cf23b61ca3d11b516efb94c35b8026