CVE-2026-89941

HIGHCVSS 7.8/10

Last modified

CVE-2026-89941 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe The `dma_fence` documentation states that if a custom release implementation is provided, the `dma_fence` object must be freed in an RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`, which might result in a use-after-free. Remove the custom `release` implementation.

Description

In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe The `dma_fence` documentation states that if a custom release implementation is provided, the `dma_fence` object must be freed in an RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`, which might result in a use-after-free. Remove the custom `release` implementation. This makes the DMA fence core fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence. This requires that the fence be the first member of `struct iio_dma_fence`. Using the default release method for extended DMA fence structures is a common pattern.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f, < 311595dc0b5621f74d8eb4dc38ef4efcdfe7e769; >= 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f, < 06a9460b8b792e109cbc934a856d02e5cff217ef; >= 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f, < 11cef99491117d4264603df159c4ff5f3845a059; >= 3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f, < 8662e56c31cf23b61ca3d11b516efb94c35b8026
LinuxLinux6.11

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89941?
In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe The `dma_fence` documentation states that if a custom release implementation is provided, the `dma_fence` object must be freed in an RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`, which might result in a use-after-free. Remove the custom `release` implementation. This makes the DMA fence core fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence. This requires that the fence be the first member of `struct iio_dma_fence`. Using the default release method for extended DMA fence structures is a common pattern.
How severe is CVE-2026-89941?
CVE-2026-89941 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-89941?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89941?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST