VYPR
Unrated severityNVD Advisory· Published Sep 16, 2026

CVE-2026-89940

CVE-2026-89940

Description

In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Tie IIO dma fence lock lifetime to the fence

The iio_dma_fence implementation currently uses a lock embedded in the iio_dmabuf_priv. But the iio_dma_fence can outlive the iio_dmabuf_priv, which can cause a use-after-free.

Tie the lifetime of the lock to the lifetime of the fence by embedding them in the same struct.

We can't just hold a reference to the iio_dmabuf_priv from the iio_dma_fence since iio_buffer_dmabuf_release() might sleep and the fence release callback is not allowed to sleep.

Note that the dma_fence framework now has an internal lock that gets used when the passing NULL for lock in dma_fence_init(), but in order to allow this patch to be backportable use an external lock.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.