dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers

Summary

CVECVE-2026-93170
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:12 UTC
Updated2026-09-17 17:18:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Fix a race condition in AXIDMA and MCDMA irq handlers where the channel could be incorrectly marked as idle and attempt spurious transfers when descriptors are still being processed. The issue occurs when: 1. Multiple descriptors are queued and active. 2. An interrupt fires after completing some descriptors. 3. xilinx_dma_complete_descriptor() moves completed descriptors to done_list. 4. Channel is marked idle and start_transfer() is called even though active_list still contains unprocessed descriptors. 5. This leads to premature transfer attempts and potential descriptor corruption or missed completions. Only mark the channel as idle and start new transfers when the active list is actually empty, ensuring proper channel state management and avoiding spurious transfer attempts.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f 7f4b989d7d87381927b98d64492f8dcf979f57ab git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f 5459e02707b27a964ae72e028d3ff72a3b687c4a git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f 425630e9eea1f9f8912b8c6abf01e0dab1e27917 git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f fdaf297ab275c6efecac5e87669c31bc89b74297 git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f c27d16fd2358b2fc3e1ffaca03afd11dc28630ea git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f ec927657524be4438447944a58173c7baf7f2384 git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f c3e943490ced0b9ad475844eda7661f6a9bcfb4a git Not specified
CNA Linux Linux affected c0bba3a99f0709c24c2c7ada7cb098966b1d791f 0b6d055edb55ecadadf54e930c2b4fab76fa9a5a git Not specified
CNA Linux Linux affected 4.7 Not specified
CNA Linux Linux unaffected 4.7 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0b6d055edb55ecadadf54e930c2b4fab76fa9a5a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7f4b989d7d87381927b98d64492f8dcf979f57ab 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/425630e9eea1f9f8912b8c6abf01e0dab1e27917 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c3e943490ced0b9ad475844eda7661f6a9bcfb4a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c27d16fd2358b2fc3e1ffaca03afd11dc28630ea 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ec927657524be4438447944a58173c7baf7f2384 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fdaf297ab275c6efecac5e87669c31bc89b74297 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5459e02707b27a964ae72e028d3ff72a3b687c4a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report