CVE-2026-80902

medium

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA When terminating DMA transfers, active descriptors are not properly reclaimed. Only cyclic descriptors were handled, leaving non-cyclic descriptors and their LLI chains to be permanently leaked. Fix by using vchan_terminate_vdesc() which handles both cyclic and non-cyclic descriptors by adding them to desc_terminated queue for proper cleanup. Add pchan->desc != pchan->done check to prevent double-adding completed descriptors, which would corrupt the list.

References

https://git.kernel.org/stable/c/d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb

https://git.kernel.org/stable/c/bb87440561eb72b47a2b848b5373b86433b247e6

https://git.kernel.org/stable/c/b150f603083cc8b72b0cbf13ec3e91f85b4390a0

https://git.kernel.org/stable/c/ab1150115e68a46b687eb38c1ab92782018c9f2c

https://git.kernel.org/stable/c/9086b488f2737d5dcee86852b83f2059f1cdfabf

https://git.kernel.org/stable/c/27806fe7b9701af0963dcd510e30e7d0cc314c43

https://git.kernel.org/stable/c/1ccc5c059d067c5358682ad5352e7d7e9239ed9b

https://git.kernel.org/stable/c/004a7a02982bed0a727a4ac7be400f00f353e7a2

Details

Source: Mitre, NVD

Published: 2026-09-04

Updated: 2026-09-04

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00165