Back

HIGH

iio: buffer: Make IIO DMA fence release RCU-safe

Published Sep 16, 2026

Description

The `dma_fence` documentation states that if a custom release implementation is provided, the `dma_fence` object must be freed in an RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`, which might result in a use-after-free.

Remove the custom `release` implementation. This makes the DMA fence core fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence. This requires that the fence be the first member of `struct iio_dma_fence`.

Using the default release method for extended DMA fence structures is a common pattern.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Sep 11, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Sep 16, 2026

Red Hat

No data

ENISA EUVD

Assigner Linux
Published Sep 16, 2026
Updated Sep 16, 2026

GitHub

No data