dmaengine: dw-edma-pcie: Reject devices without driver data
Published Aug 15, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
dw_edma_pcie_probe() treats the PCI device ID driver_data as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference.
Reject such matches before enabling the device.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.3StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.3
- Version 6.12.101StatusunaffectedConstraints<=6.12.*
- Version 6.18.42StatusunaffectedConstraints<=6.18.*
- Version 6.6.148StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-72147 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516658 Issue Tracking
- https://git.kernel.org/stable/c/043acb00e4edd4b9ffb9dd0e357482dcd9086486
- https://git.kernel.org/stable/c/044f7b3252d4fb2143d4999eec2800c08f1001ed
- https://git.kernel.org/stable/c/11d7cfe0c119691b2dafbb699bbca90258c678aa
- https://git.kernel.org/stable/c/2733b5dcb5a4ba4446f7bac954b97e4501dcaa64
- https://git.kernel.org/stable/c/a1042599fa8f9e313be176eb1ea1ae199f983419
- https://lore.kernel.org/linux-cve-announce/2026081533-CVE-2026-72147-7d3c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72147
- https://www.cve.org/CVERecord?id=CVE-2026-72147
Change history (0)
No recorded changes yet.