{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89994","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.780Z","datePublished":"2026-09-16T10:33:07.292Z","dateUpdated":"2026-09-16T14:41:08.470Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:41:08.470Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-edma: tracing: no ptr dereference during log output\n\nThe fsl edma events store a pointer to a struct fsl_edma_engine in the\nringbuffer and dereference it when a log entry is printed. At this time,\nthe pointer may no longer be valid.\n\nEvent injection can be used to trigger a crash:\n\n$ cd /sys/kernel/tracing\n$ echo 'value = 0' > events/fsl_edma/edma_writeb/inject\n$ cat trace\n\nThe log output needs only edma->membase. Add a membase field at the end\nof the event and use the new field for log output. Keep the existing\nfields for backward compatibility."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The stale dereference runs only when a local actor reads formatted fsl_edma events from tracefs (/sys/kernel/tracing/trace or trace_pipe). DMA MMIO tracing and event injection only enqueue ring-buffer records; there is no network, adjacent-radio, or physical-device path into TP_printk().\nAC:L - An attacker with tracefs access controls the full sequence: enable edma_log_io events, either inject a record via events/fsl_edma/*/inject or generate eDMA I/O then unbind/remove fsl-edma so the stored engine pointer is freed, then read trace. No race or uninfluenced victim state is required.\nPR:L - tracing_check_open_get_tr() enforces only LOCKDOWN_TRACEFS and DAC, with no capable() check. Event enable and trace files are mode 0640 and are routinely delegated via tracefs gid= to tracing-group members on Android Automotive/NXP i.MX, ChromeOS, and developer kernels, matching prior TP_printk UAF CVEs.\nUI:N - No victim interaction is required. The attacker enables fsl_edma events, injects or records a stale edma pointer, and reads the formatted trace themselves to invoke the vulnerable TP_printk() path.\nS:U - Impact stays inside the host kernel's trace formatting path (stale fsl_edma_engine dereference). This is standard local kernel memory-safety impact with no VM escape, IOMMU/DMA boundary bypass, or other cross-authority effect; membase is used only for log offset arithmetic.\nC:H - TP_printk() dereferences __entry->edma->membase when formatting output. That is a use-after-free read of a freed fsl_edma_engine, and with event injection the edma field is attacker-chosen, yielding an arbitrary kernel pointer read whose result is printed as the register offset.\nI:H - The bug is a use-after-free of the kernel heap object fsl_edma_engine, which embeds dma_device function pointers. Freed memory can be reclaimed before the trace read, enabling heap grooming and write/control-flow primitives; kernel CNA guidance rates UAF integrity impact as High.\nA:H - Dereferencing a NULL (inject with a zeroed edma pointer) or freed fsl_edma_engine pointer during trace formatting causes a kernel oops or panic. The fix commit demonstrates a deterministic crash via inject followed by cat trace."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/fsl-edma-trace.h"],"versions":[{"version":"11102d0c343ba06ddd303f2503c0ce46d70052f2","lessThan":"ef02cd3807f39ae1dbc924788d8fa6a85334c435","status":"affected","versionType":"git"},{"version":"11102d0c343ba06ddd303f2503c0ce46d70052f2","lessThan":"d382aaf5fed38c6dd2e0cc710d97cb81d660ffa7","status":"affected","versionType":"git"},{"version":"11102d0c343ba06ddd303f2503c0ce46d70052f2","lessThan":"2a3801ae5c344473e648006c5b03a9216ac54a6a","status":"affected","versionType":"git"},{"version":"11102d0c343ba06ddd303f2503c0ce46d70052f2","lessThan":"2ea04dca8e627f722caa7a2037cfbae0257f3501","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/fsl-edma-trace.h"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ef02cd3807f39ae1dbc924788d8fa6a85334c435"},{"url":"https://git.kernel.org/stable/c/d382aaf5fed38c6dd2e0cc710d97cb81d660ffa7"},{"url":"https://git.kernel.org/stable/c/2a3801ae5c344473e648006c5b03a9216ac54a6a"},{"url":"https://git.kernel.org/stable/c/2ea04dca8e627f722caa7a2037cfbae0257f3501"}],"title":"dmaengine: fsl-edma: tracing: no ptr dereference during log output","x_generator":{"engine":"bippy-1.2.0"}}}}