CVE-2026-80902 PUBLISHED

dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA

When terminating DMA transfers, active descriptors are not properly reclaimed. Only cyclic descriptors were handled, leaving non-cyclic descriptors and their LLI chains to be permanently leaked.

Fix by using vchan_terminate_vdesc() which handles both cyclic and non-cyclic descriptors by adding them to desc_terminated queue for proper cleanup.

Add pchan->desc != pchan->done check to prevent double-adding completed descriptors, which would corrupt the list.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to bb87440561eb72b47a2b848b5373b86433b247e6 (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to 004a7a02982bed0a727a4ac7be400f00f353e7a2 (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to b150f603083cc8b72b0cbf13ec3e91f85b4390a0 (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to 27806fe7b9701af0963dcd510e30e7d0cc314c43 (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to 1ccc5c059d067c5358682ad5352e7d7e9239ed9b (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to 9086b488f2737d5dcee86852b83f2059f1cdfabf (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb (excl.)
  • affected from 555859308723d8d5b828304f5eb9281143fd86b5 to ab1150115e68a46b687eb38c1ab92782018c9f2c (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.17 is affected
  • unaffected from 0 to 3.17 (excl.)
  • unaffected from 5.10.265 to 5.10.* (incl.)
  • unaffected from 5.15.216 to 5.15.* (incl.)
  • unaffected from 6.1.183 to 6.1.* (incl.)
  • unaffected from 6.6.151 to 6.6.* (incl.)
  • unaffected from 6.12.103 to 6.12.* (incl.)
  • unaffected from 6.18.44 to 6.18.* (incl.)
  • unaffected from 7.1.8 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References