CVE-2026-93042
8.8Linux · Kernel
A flaw in the Linux kernel dmaengine dw-edma driver allows for potential use-after-free conditions and memory leaks due to improper termination of DMA descriptors without correct callback handling.
Executive summary
A critical vulnerability in the Linux kernel dw-edma driver could allow an unauthenticated attacker to trigger memory corruption or system instability.
Vulnerability
The vulnerability resides in the dw-edma driver where incomplete transfers improperly trigger callbacks. This allows an unauthenticated attacker to cause a use-after-free condition by dereferencing freed client state or leaking buffer memory.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to system crashes, denial of service, or potentially arbitrary code execution depending on the state of the kernel memory, which poses a significant risk to the stability and integrity of affected production environments.
Remediation
Immediate Action: Update the Linux kernel to version 6.6.157, 6.12.110, 6.18.52, or 7.2.6 as provided by your distribution vendor.
Proactive Monitoring: Monitor system logs for kernel panic events or unexplained driver-related resource exhaustion that may indicate attempted exploitation.
Compensating Controls: Restrict access to hardware interfaces that utilize the dw-edma driver to authorized users or processes to limit the attack surface.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the severity of potential kernel-level memory corruption, administrators should prioritize patching the Linux kernel across all affected infrastructure. Apply the recommended stable kernel updates immediately to eliminate the risk of memory-based exploitation.
More Linux CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section