iio: buffer: Tie IIO dma fence lock lifetime to the fence
Published Sep 16, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
The `iio_dma_fence` implementation currently uses a lock embedded in the `iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the `iio_dmabuf_priv`, which can cause a use-after-free.
Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct.
We can't just hold a reference to the `iio_dmabuf_priv` from the `iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the fence release callback is not allowed to sleep.
Note that the `dma_fence` framework now has an internal lock that gets used when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to allow this patch to be backportable use an external lock.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.11StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.11
- Version 6.12.110StatusunaffectedConstraints<=6.12.*
- Version 6.18.51StatusunaffectedConstraints<=6.18.*
- Version 7.2.5StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (4)
- https://git.kernel.org/stable/c/510497e31be4f241103507315a859e2085ccb081
- https://git.kernel.org/stable/c/6865d79fca17a80fbd60c12550ca9a5e0e20e0eb
- https://git.kernel.org/stable/c/8b3e221590181a8beb3735bbabf166df02c839b5
- https://git.kernel.org/stable/c/f25ec4627d935dedfb5fe83bd2c2678cdcc19611
Change history (0)
No recorded changes yet.