CVE-2026-89994

HIGHCVSS 7.8/10

Last modified

CVE-2026-89994 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference during log output The fsl edma events store a pointer to a struct fsl_edma_engine in the ringbuffer and dereference it when a log entry is printed. At this time, the pointer may no longer be valid. Event injection can be used to trigger a crash: $ cd /sys/kernel/tracing $ echo 'value = 0' > events/fsl_edma/edma_writeb/inject $ cat trace The log output needs only edma->membase.

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference during log output The fsl edma events store a pointer to a struct fsl_edma_engine in the ringbuffer and dereference it when a log entry is printed. At this time, the pointer may no longer be valid. Event injection can be used to trigger a crash: $ cd /sys/kernel/tracing $ echo 'value = 0' > events/fsl_edma/edma_writeb/inject $ cat trace The log output needs only edma->membase. Add a membase field at the end of the event and use the new field for log output. Keep the existing fields for backward compatibility.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 11102d0c343ba06ddd303f2503c0ce46d70052f2, < ef02cd3807f39ae1dbc924788d8fa6a85334c435; >= 11102d0c343ba06ddd303f2503c0ce46d70052f2, < d382aaf5fed38c6dd2e0cc710d97cb81d660ffa7; >= 11102d0c343ba06ddd303f2503c0ce46d70052f2, < 2a3801ae5c344473e648006c5b03a9216ac54a6a; >= 11102d0c343ba06ddd303f2503c0ce46d70052f2, < 2ea04dca8e627f722caa7a2037cfbae0257f3501
LinuxLinux6.10

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89994?
In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference during log output The fsl edma events store a pointer to a struct fsl_edma_engine in the ringbuffer and dereference it when a log entry is printed. At this time, the pointer may no longer be valid. Event injection can be used to trigger a crash: $ cd /sys/kernel/tracing $ echo 'value = 0' > events/fsl_edma/edma_writeb/inject $ cat trace The log output needs only edma->membase. Add a membase field at the end of the event and use the new field for log output. Keep the existing fields for backward compatibility.
How severe is CVE-2026-89994?
CVE-2026-89994 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-89994?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89994?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST