{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72146","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.908Z","datePublished":"2026-08-15T05:53:18.431Z","dateUpdated":"2026-08-19T16:36:26.048Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:36:26.048Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sh: rz-dmac: Move interrupt request after everything is set up\n\nOnce the interrupt is requested, the interrupt handler may run immediately.\nSince the IRQ handler can access channel->ch_base, which is initialized\nonly after requesting the IRQ, this may lead to invalid memory access.\nLikewise, the IRQ thread may access uninitialized data (the ld_free,\nld_queue, and ld_active lists), which may also lead to issues.\n\nRequest the interrupts only after everything is set up. To keep the error\npath simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw triggers in rz_dmac_chan_probe() during Renesas RZ/G2L/V2H/T2H platform DMAC driver initialization at boot or module load; there is no network, Bluetooth, or runtime syscall path to the vulnerable devm_request_threaded_irq() ordering.\nAC:L - Once the DMAC channel IRQ line is asserted when devm_request_threaded_irq() is called after reset_deassert, the hardirq/thread handlers run immediately before ch_base or lists are initialized; stale post-reset interrupt state on these SoCs makes this timing plausible without luck.\nPR:N - rz_dmac_probe() performs no capability or authentication checks before requesting per-channel IRQs; on affected Renesas embedded boards the vulnerable probe sequence runs automatically during kernel boot without the attacker holding Linux privileges.\nUI:N - No victim action is required; pending/latched DMAC channel interrupts during driver probe at boot or reboot can invoke the buggy handlers without anyone opening device nodes or configuring DMA transfers.\nS:U - Impact is kernel NULL dereference, list/spinlock corruption, and MMIO faults within the host kernel; this is not a VM escape, container sandbox breakout, or documented IOMMU security-boundary bypass.\nC:H - The threaded IRQ handler may lock an uninitialized vc.lock and walk uninitialized ld_active/ld_queue/ld_free lists, causing invalid kernel memory reads and list-metadata exposure beyond a pure bounded fault.\nI:H - The hardirq path issues readl/writel through uninitialized ch_base (NULL/low MMIO), and list/spinlock corruption in the IRQ thread can corrupt kernel heap metadata and enable control-flow hijack primitives.\nA:H - Invalid MMIO via NULL ch_base and corrupted IRQ-thread list handling can cause kernel oops/panic during probe on affected embedded systems, causing full loss of availability until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/sh/rz-dmac.c"],"versions":[{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"d24d53323e817d79a4bd111bd10b34dbc96e64a8","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"5b12de6229d662864ee22c11d4876652b40120f0","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"ec9f66c91bffdb69d309bae6dfb387562db7ebc8","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"07ae600bd353b22f31a8f1007269744fafc7f123","status":"affected","versionType":"git"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"731712403ddb39d1a76a11abf339a0615bc85de7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/sh/rz-dmac.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d24d53323e817d79a4bd111bd10b34dbc96e64a8"},{"url":"https://git.kernel.org/stable/c/0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f"},{"url":"https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0"},{"url":"https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93"},{"url":"https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8"},{"url":"https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123"},{"url":"https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7"}],"title":"dmaengine: sh: rz-dmac: Move interrupt request after everything is set up","x_generator":{"engine":"bippy-1.2.0"}}}}