{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98243","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.330Z","datePublished":"2026-10-06T08:45:13.411Z","dateUpdated":"2026-10-07T06:49:37.540Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:37.540Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3\n\nThe patch \"dma-buf: dma-fence: Fix potential NULL pointer dereference\"\nchanged the check to test for the ops pointer instead of the signaled\nbit to avoid a potential NULL dereference when the ops pointer has been\ncleared.\n\nThe problem is now that the ops pointer is cleared only when neither the\nrelease nor the wait callback is implemented and this isn't true for a lot\nof dma_fence implementations yet. So those implementations lost the RCU\nprotection after signaling of the returned string resulting in potential\nuse after free.\n\nAdd the signaling check additional to the ops pointer check so that we\nhave both the protection against NULL dereference as well as the RCU\nprotection after signaling for the returned string.\n\nv2: improve comments to note RCU protection and explain why we check\n    both signaling state and ops pointer\nv3: some comment improvements suggested by Philip"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the local SYNC_IOC_FILE_INFO ioctl on a sync_file fd (sync_file_ioctl_fence_info -> sync_fill_fence_info -> dma_fence_timeline_name/dma_fence_driver_name). No network protocol carries data into this path.\nAC:L - The attacker produces the whole state: create an xe exec queue, submit a job, export the out-fence as a sync_file, destroy the queue, wait for signal plus an RCU grace period, then call the ioctl. The kfree_rcu'd scheduler is then read deterministically.\nPR:L - Needs an ordinary unprivileged user who can open a DRM render node (render group or seat ACL) to create exec queues and export syncobj fences as sync_files; no root or CAP_SYS_ADMIN is required.\nUI:N - The attacker performs every step through their own ioctls on objects they own; no other user or administrator has to act.\nS:U - The use-after-free is a kernel memory read inside the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Since ops stays non-NULL after signal, drm_sched_fence_get_timeline_name dereferences fence->sched inside the freed xe guc exec-queue object and strscpy's the string at the loaded name pointer into info->obj_name, which is copied to userspace; a sprayed fake pointer gives a kernel read-out.\nI:N - The freed scheduler is only read: get_timeline_name/get_driver_name load a pointer and the caller copies a string from it. No write or indirect call goes through freed memory, so the code shows no write primitive.\nA:H - If the freed scheduler slot is reused, sched->name becomes a garbage pointer; strscpy/snprintf on it can fault and oops the kernel, and an unprivileged user can trigger this repeatedly."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma-buf/dma-fence.c","include/linux/dma-fence.h"],"versions":[{"version":"035219a760edb35ae9a9e96beba7f122e26a997b","lessThan":"a4db25b8949d6ff9c1a685a1273a015e8bab29db","status":"affected","versionType":"git"},{"version":"035219a760edb35ae9a9e96beba7f122e26a997b","lessThan":"3ed11c671ff7ec58c8fd96410233c677df23f407","status":"affected","versionType":"git"},{"version":"15ecfdf0ef6f6d874d0a26690d300857b39ebfd0","status":"affected","versionType":"git"},{"version":"7.1.5","lessThan":"7.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma-buf/dma-fence.c","include/linux/dma-fence.h"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a4db25b8949d6ff9c1a685a1273a015e8bab29db"},{"url":"https://git.kernel.org/stable/c/3ed11c671ff7ec58c8fd96410233c677df23f407"}],"title":"dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3","x_generator":{"engine":"bippy-1.2.0"}}}}