CVE-2026-98243 (GCVE-0-2026-98243)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-07 06:49
VLAI
Title
dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3
Summary
In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 The patch "dma-buf: dma-fence: Fix potential NULL pointer dereference" changed the check to test for the ops pointer instead of the signaled bit to avoid a potential NULL dereference when the ops pointer has been cleared. The problem is now that the ops pointer is cleared only when neither the release nor the wait callback is implemented and this isn't true for a lot of dma_fence implementations yet. So those implementations lost the RCU protection after signaling of the returned string resulting in potential use after free. Add the signaling check additional to the ops pointer check so that we have both the protection against NULL dereference as well as the RCU protection after signaling for the returned string. v2: improve comments to note RCU protection and explain why we check both signaling state and ops pointer v3: some comment improvements suggested by Philip
Impacted products
Vendor Product Version
Linux Linux Affected: 035219a760edb35ae9a9e96beba7f122e26a997b , < a4db25b8949d6ff9c1a685a1273a015e8bab29db (git)
Affected: 035219a760edb35ae9a9e96beba7f122e26a997b , < 3ed11c671ff7ec58c8fd96410233c677df23f407 (git)
Affected: 15ecfdf0ef6f6d874d0a26690d300857b39ebfd0 (git)
Affected: 7.1.5 , < 7.2 (semver)
Create a notification for this product.
Linux Linux Affected: 7.2
Unaffected: 0 , < 7.2 (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/dma-buf/dma-fence.c",
            "include/linux/dma-fence.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "a4db25b8949d6ff9c1a685a1273a015e8bab29db",
              "status": "affected",
              "version": "035219a760edb35ae9a9e96beba7f122e26a997b",
              "versionType": "git"
            },
            {
              "lessThan": "3ed11c671ff7ec58c8fd96410233c677df23f407",
              "status": "affected",
              "version": "035219a760edb35ae9a9e96beba7f122e26a997b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "15ecfdf0ef6f6d874d0a26690d300857b39ebfd0",
              "versionType": "git"
            },
            {
              "lessThan": "7.2",
              "status": "affected",
              "version": "7.1.5",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/dma-buf/dma-fence.c",
            "include/linux/dma-fence.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "lessThan": "7.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "7.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "7.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "7.1.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3\n\nThe patch \"dma-buf: dma-fence: Fix potential NULL pointer dereference\"\nchanged the check to test for the ops pointer instead of the signaled\nbit to avoid a potential NULL dereference when the ops pointer has been\ncleared.\n\nThe problem is now that the ops pointer is cleared only when neither the\nrelease nor the wait callback is implemented and this isn\u0027t true for a lot\nof dma_fence implementations yet. So those implementations lost the RCU\nprotection after signaling of the returned string resulting in potential\nuse after free.\n\nAdd the signaling check additional to the ops pointer check so that we\nhave both the protection against NULL dereference as well as the RCU\nprotection after signaling for the returned string.\n\nv2: improve comments to note RCU protection and explain why we check\n    both signaling state and ops pointer\nv3: some comment improvements suggested by Philip"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached through the local SYNC_IOC_FILE_INFO ioctl on a sync_file fd (sync_file_ioctl_fence_info -\u003e sync_fill_fence_info -\u003e dma_fence_timeline_name/dma_fence_driver_name). No network protocol carries data into this path.\nAC:L - The attacker produces the whole state: create an xe exec queue, submit a job, export the out-fence as a sync_file, destroy the queue, wait for signal plus an RCU grace period, then call the ioctl. The kfree_rcu\u0027d scheduler is then read deterministically.\nPR:L - Needs an ordinary unprivileged user who can open a DRM render node (render group or seat ACL) to create exec queues and export syncobj fences as sync_files; no root or CAP_SYS_ADMIN is required.\nUI:N - The attacker performs every step through their own ioctls on objects they own; no other user or administrator has to act.\nS:U - The use-after-free is a kernel memory read inside the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Since ops stays non-NULL after signal, drm_sched_fence_get_timeline_name dereferences fence-\u003esched inside the freed xe guc exec-queue object and strscpy\u0027s the string at the loaded name pointer into info-\u003eobj_name, which is copied to userspace; a sprayed fake pointer gives a kernel read-out.\nI:N - The freed scheduler is only read: get_timeline_name/get_driver_name load a pointer and the caller copies a string from it. No write or indirect call goes through freed memory, so the code shows no write primitive.\nA:H - If the freed scheduler slot is reused, sched-\u003ename becomes a garbage pointer; strscpy/snprintf on it can fault and oops the kernel, and an unprivileged user can trigger this repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:37.540Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a4db25b8949d6ff9c1a685a1273a015e8bab29db"
        },
        {
          "url": "https://git.kernel.org/stable/c/3ed11c671ff7ec58c8fd96410233c677df23f407"
        }
      ],
      "title": "dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98243",
    "datePublished": "2026-10-06T08:45:13.411Z",
    "dateReserved": "2026-09-25T10:25:14.330Z",
    "dateUpdated": "2026-10-07T06:49:37.540Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98243",
      "date": "2026-10-09",
      "epss": "0.00122",
      "percentile": "0.01809"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/dma-buf/dma-fence.c",
                  "include/linux/dma-fence.h"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "a4db25b8949d6ff9c1a685a1273a015e8bab29db",
                    "status": "affected",
                    "version": "035219a760edb35ae9a9e96beba7f122e26a997b",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "3ed11c671ff7ec58c8fd96410233c677df23f407",
                    "status": "affected",
                    "version": "035219a760edb35ae9a9e96beba7f122e26a997b",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "15ecfdf0ef6f6d874d0a26690d300857b39ebfd0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "7.2",
                    "status": "affected",
                    "version": "7.1.5",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/dma-buf/dma-fence.c",
                  "include/linux/dma-fence.h"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "lessThan": "7.2",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3\n\nThe patch \"dma-buf: dma-fence: Fix potential NULL pointer dereference\"\nchanged the check to test for the ops pointer instead of the signaled\nbit to avoid a potential NULL dereference when the ops pointer has been\ncleared.\n\nThe problem is now that the ops pointer is cleared only when neither the\nrelease nor the wait callback is implemented and this isn\u0027t true for a lot\nof dma_fence implementations yet. So those implementations lost the RCU\nprotection after signaling of the returned string resulting in potential\nuse after free.\n\nAdd the signaling check additional to the ops pointer check so that we\nhave both the protection against NULL dereference as well as the RCU\nprotection after signaling for the returned string.\n\nv2: improve comments to note RCU protection and explain why we check\n    both signaling state and ops pointer\nv3: some comment improvements suggested by Philip"
          }
        ],
        "id": "CVE-2026-98243",
        "lastModified": "2026-10-07T07:17:06.120",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.2,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:12.383",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/3ed11c671ff7ec58c8fd96410233c677df23f407"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/a4db25b8949d6ff9c1a685a1273a015e8bab29db"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:49:29Z",
      "cve": "CVE-2026-98243",
      "id": "CVE-2026-98243",
      "initial_release_date": "2026-10-08T16:49:29Z",
      "product_status:known_not_affected": "347",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98243",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98243.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…