From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72146: dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
Date: Sat, 15 Aug 2026 15:03:45 +0900 [thread overview]
Message-ID: <2026081533-CVE-2026-72146-5f98@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
Once the interrupt is requested, the interrupt handler may run immediately.
Since the IRQ handler can access channel->ch_base, which is initialized
only after requesting the IRQ, this may lead to invalid memory access.
Likewise, the IRQ thread may access uninitialized data (the ld_free,
ld_queue, and ld_active lists), which may also lead to issues.
Request the interrupts only after everything is set up. To keep the error
path simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent().
The Linux kernel CVE team has assigned CVE-2026-72146 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.15 with commit 5000d37042a61ca556fde2782ca40dbfa802ea16 and fixed in 6.6.148 with commit 5b12de6229d662864ee22c11d4876652b40120f0
Issue introduced in 5.15 with commit 5000d37042a61ca556fde2782ca40dbfa802ea16 and fixed in 6.12.101 with commit 2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93
Issue introduced in 5.15 with commit 5000d37042a61ca556fde2782ca40dbfa802ea16 and fixed in 6.18.42 with commit ec9f66c91bffdb69d309bae6dfb387562db7ebc8
Issue introduced in 5.15 with commit 5000d37042a61ca556fde2782ca40dbfa802ea16 and fixed in 7.1.5 with commit 07ae600bd353b22f31a8f1007269744fafc7f123
Issue introduced in 5.15 with commit 5000d37042a61ca556fde2782ca40dbfa802ea16 and fixed in 7.2-rc1 with commit 731712403ddb39d1a76a11abf339a0615bc85de7
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72146
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/dma/sh/rz-dmac.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0
https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93
https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8
https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123
https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7
reply other threads:[~2026-08-15 6:13 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081533-CVE-2026-72146-5f98@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.