{"id":"AZL-102653","summary":"CVE-2026-93041 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: Serialize abort state updates\n\ndw_edma_abort_interrupt() drops vc.lock before changing request and\nstatus. issue_pending() can acquire the lock in that small window,\nobserve the old busy state, and skip starting queued descriptors. Then\nthe abort handler overwrites the channel status as idle, leaving the new\ndescriptors stranded for good.\n\nKeep descriptor completion and the state transition in the same critical\nsection.","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:17:57Z","upstream":["CVE-2026-93041"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93041"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102653.json"}}],"schema_version":"1.9.0"}