iio: buffer: Make IIO DMA fence release RCU-safe
Published Sep 16, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
The `dma_fence` documentation states that if a custom release implementation is provided, the `dma_fence` object must be freed in an RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`, which might result in a use-after-free.
Remove the custom `release` implementation. This makes the DMA fence core fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence. This requires that the fence be the first member of `struct iio_dma_fence`.
Using the default release method for extended DMA fence structures is a common pattern.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 6.11
Unaffected
- ≥ 0, < 6.11
- ≥ 6.12.110, ≤ 6.12.*
- ≥ 6.18.51, ≤ 6.18.*
- ≥ 7.2.5, ≤ 7.2.*
- 7.3-rc1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80541 Advisory
- https://git.kernel.org/stable/c/06a9460b8b792e109cbc934a856d02e5cff217ef
- https://git.kernel.org/stable/c/11cef99491117d4264603df159c4ff5f3845a059
- https://git.kernel.org/stable/c/311595dc0b5621f74d8eb4dc38ef4efcdfe7e769
- https://git.kernel.org/stable/c/8662e56c31cf23b61ca3d11b516efb94c35b8026
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data