Sceawere
Vulnerability Detail
CVE-2026-98243UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Kernel dma-buf Use-After-Free
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 The patch "dma-buf: dma-fence: Fix potential NULL pointer dereference" changed the check to test for the ops pointer instead of the signaled bit to avoid a potential NULL dereference when the ops pointer has been cleared. The problem is now that the ops pointer is cleared only when neither the release nor the wait callback is implemented and this isn't true for a lot of dma_fence implementations yet. So those implementations lost the RCU protection after signaling of the returned string resulting in potential use after free. Add the signaling check additional to the ops pointer check so that we have both the protection against NULL dereference as well as the RCU protection after signaling for the returned string. v2: improve comments to note RCU protection and explain why we check both signaling state and ops pointer v3: some comment improvements suggested by Philip
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:18:12.383Z",
"pubdate": "2026-10-06T09:18:12.383Z",
"executiveSummary": "This vulnerability is a use-after-free (UAF) condition identified within the Linux kernel's dma-buf/dma-fence subsystem. The flaw originates from an improper synchronization mechanism when accessing dma-fence strings, specifically regarding RCU protection during the signaling state.\nThe vulnerability type is a use-after-free resulting from insufficient pointer validation, which can lead to memory corruption or potential local privilege escalation (LPE). The affected product is the Linux kernel, specifically components utilizing the dma-fence framework for synchronization.\nThe security risk is significant as it allows for unauthorized memory access if an attacker can trigger the premature freeing of the dma-fence object while a process is attempting to access the timeline or driver name string. Successful exploitation generally requires an attacker to have local access to the system to invoke specific system calls that interact with the dma-buf subsystem. No remote network exploitation vector is directly identified for this specific issue, though local unprivileged users may potentially leverage this flaw to destabilize the kernel or escalate privileges.",
"technicalDetails": "The root cause of this vulnerability lies in an incomplete fix for a previously identified NULL pointer dereference. Initially, developers modified the dma-fence implementation to check the 'ops' (operations) pointer rather than the 'signaled' bit to prevent a NULL pointer dereference when accessing fence metadata. However, the 'ops' pointer is only cleared under specific conditions where neither the 'release' nor the 'wait' callbacks are implemented. Because many dma-fence implementations still define these callbacks, the 'ops' pointer remains non-NULL after the fence has been signaled.\nThe logical error occurs because the transition to 'ops' pointer checking prematurely terminates RCU (Read-Copy-Update) protection for the returned string (timeline or driver name). RCU provides a mechanism to safely access data that might be removed by concurrent threads. By relying solely on the 'ops' pointer check, the kernel fails to verify the 'signaled' state, which is the actual indicator that the object's life cycle has concluded and its memory is available for reclamation. As a result, if the fence object is freed after signaling but before the string access completes, the system performs a use-after-free on the string memory.\nThe exploitation flow involves a race condition. An attacker must trigger the signaling of a dma-fence while another kernel process is simultaneously invoking a function that reads the fence's driver name or timeline string. If the attacker can influence the timing of the fence object's destruction, they can ensure the target string memory is freed or reallocated. When the reader process subsequently accesses the pointer, it reads stale or malicious data from the freed memory area. This leads to unpredictable kernel behavior, memory corruption, or information disclosure.\nThe vulnerable component is located within the dma-fence infrastructure, specifically affecting the routines that retrieve fence metadata. The vulnerability exists across Linux kernel versions where the previous NULL pointer dereference patch was applied but lacked the auxiliary signaling bit check. The vulnerability does not require complex remote authentication, as it is an internal kernel-level memory management flaw triggered via standard dma-buf system calls. The impact post-exploitation can range from system crashes (Kernel Panic) to the hijacking of control flow if the attacker can influence the contents of the reallocated memory."
}