CVE-2026-98343 is a vulnerability in Linux Kernel
Published on October 6, 2026
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Products Associated with CVE-2026-98343
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below b92c502595336a3cc5bb7a060170891366745a5d is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below 855187a88bdf762c46b6849307597e3e02bfc1d9 is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below c9780b601438137494b407eb4301bb3de2587ac9 is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below 07eb075b60d565a5e465a1945a80cc62807492ad is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below 9319dd64d5cdef851841c091f30424faa2284c31 is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below 6cf31716b77a71c0d634106f4f3951377b8dc6dc is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below 02bd02c585293634b213b142cba63cbf77891f6b is affected.
- Version 8ad342a863590b24ce77681b7e081363fb3333f7 and below e873c74132f0c5f1452816cd9bb26208f0bba1e1 is affected.
- Version 5.6 is affected.
- Before 5.6 is unaffected.
- Version 5.10.271, <= 5.10.* is unaffected.
- Version 5.15.222, <= 5.15.* is unaffected.
- Version 6.1.189, <= 6.1.* is unaffected.
- Version 6.6.158, <= 6.6.* is unaffected.
- Version 6.12.112, <= 6.12.* is unaffected.
- Version 6.18.54, <= 6.18.* is unaffected.
- Version 7.2.8, <= 7.2.* is unaffected.
- Version 7.3-rc4, <= * is unaffected.