{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93042","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T15:57:05.657Z","datePublished":"2026-09-17T16:10:34.911Z","dateUpdated":"2026-09-18T17:55:44.317Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:44.317Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: Terminate all descriptors without callbacks\n\nThe DMA Engine client documentation says in the \"Terminate APIs\" section\nof Documentation/driver-api/dmaengine/client.rst:\n\n\"No callback functions will be called for any incomplete transfers.\"\n\ndw-edma instead calls vchan_cookie_complete() when a deferred STOP reaches\nthe interrupt handler. This schedules a callback for the active descriptor\nand leaves other issued or submitted descriptors queued. A late callback\nafter dmaengine_terminate_sync() can dereference client state that has\nalready been freed, while leftover descriptors may later restart into\nreused buffers or leak.\n\nMove all issued and submitted descriptors to the terminated list whenever\ntermination completes. For a pending STOP, do this from both the DONE and\nABORT paths. Complete their cookies in order without scheduling callbacks.\n\nA STOP can remain pending until the running transfer raises an\ninterrupt. Make device_synchronize() wait for such a pending STOP to\ncomplete before releasing terminated descriptors. Reuse it from\nfree_chan_resources(), then release the remaining virt-dma resources.\nSleep instead of busy-polling while waiting, and warn if the existing\ntimeout expires."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - On DesignWare PCIe endpoint SoCs the host starts eDMA via pci_epf_mhi_edma_read()/write() (MHI transfers ≥4K), nvmet_pci_epf_dma_transfer(), or pci_epf_test BAR COMMAND_READ|WRITE with FLAG_USE_DMA, then those clients call dmaengine_terminate_sync() on the local dw-edma channel; the trigger is PCIe-link peer traffic, not a local syscall or a routable protocol.\nAC:L - pci_epf_mhi_edma_read() waits only 1000ms then calls dmaengine_terminate_sync(); a host that issues a ≥4K MHI DMA and stalls it hits that timeout while EDMA_ST_BUSY. Vulnerable dw_edma_device_terminate_all() only stores EDMA_REQ_STOP and returns 0 because device_synchronize was unimplemented, so the host can drop the stall and deliver the DONE/ABORT IRQ itself.\nPR:N - pci_epf_mhi_edma_read()/write() and nvmet_pci_epf_dma_transfer() do not authenticate the PCIe host; MHI TREs, NVMe I/O, or BAR command-register COMMAND_READ/WRITE writes from the upstream port suffice, with no Linux uid, capability, or user-namespace check on the endpoint.\nUI:N - The PCIe host starts the MHI/NVMe/epf-test DMA and forces the client's terminate-on-timeout path itself; no victim mount, file open, or other interactive step is required once the endpoint function is already bound.\nS:U - The late vchan_complete() callback UAF and leftover desc_issued restarts corrupt callback state and DMA buffers inside the same endpoint kernel that hosts dw-edma; that is in-kernel memory corruption, not a KVM/Xen guest escape or an IOMMU policy bypass.\nC:H - dw_edma_done_interrupt()'s EDMA_REQ_STOP path calls vchan_cookie_complete(), so vchan_complete() can invoke pci_epf_mhi_dma_callback() after pci_epf_mhi_edma_read() returned and its DECLARE_COMPLETION_ONSTACK died; leftover issued descriptors can also dw_edma_start_transfer() MEM_TO_DEV from reused kernel pages into host memory.\nI:H - After dma_unmap_single() in the MHI/nvmet timeout path, leftover desc_issued entries stay queued, so a later issue_pending() runs dw_edma_start_transfer() DEV_TO_MEM into those unmapped/reused pages, and the late callback UAF likewise corrupts kernel state, giving a write primitive.\nA:H - The STOP-path vchan_cookie_complete() UAF in vchan_complete() and DMA into buffers already unmapped by pci_epf_mhi_edma_read() or nvmet_pci_epf_dma_transfer() oops or panic the endpoint kernel, as the fix commit describes for a late callback after dmaengine_terminate_sync()."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/dw-edma/dw-edma-core.c"],"versions":[{"version":"e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf","lessThan":"65e387b95d3855aa894ac729e1778e5bcb9083cb","status":"affected","versionType":"git"},{"version":"e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf","lessThan":"4793f9099a1cadf4e37f3a03d524af6bce88a0ea","status":"affected","versionType":"git"},{"version":"e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf","lessThan":"be87d86537de7ea6fd025f41033d2faff880973f","status":"affected","versionType":"git"},{"version":"e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf","lessThan":"f3ec6702a1d216be61f692cc0a983d6c8fb5ebf7","status":"affected","versionType":"git"},{"version":"e63d79d1ffcd2201a2dbff1d7a1184b8f3ec74cf","lessThan":"99109a51efd28c9a661fbfb9469b023c517b31d1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/dw-edma/dw-edma-core.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/65e387b95d3855aa894ac729e1778e5bcb9083cb"},{"url":"https://git.kernel.org/stable/c/4793f9099a1cadf4e37f3a03d524af6bce88a0ea"},{"url":"https://git.kernel.org/stable/c/be87d86537de7ea6fd025f41033d2faff880973f"},{"url":"https://git.kernel.org/stable/c/f3ec6702a1d216be61f692cc0a983d6c8fb5ebf7"},{"url":"https://git.kernel.org/stable/c/99109a51efd28c9a661fbfb9469b023c517b31d1"}],"title":"dmaengine: dw-edma: Terminate all descriptors without callbacks","x_generator":{"engine":"bippy-1.2.0"}}}}