{"id":"CVE-2026-89994","summary":"dmaengine: fsl-edma: tracing: no ptr dereference during log output","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-edma: tracing: no ptr dereference during log output\n\nThe fsl edma events store a pointer to a struct fsl_edma_engine in the\nringbuffer and dereference it when a log entry is printed. At this time,\nthe pointer may no longer be valid.\n\nEvent injection can be used to trigger a crash:\n\n$ cd /sys/kernel/tracing\n$ echo 'value = 0' \u003e events/fsl_edma/edma_writeb/inject\n$ cat trace\n\nThe log output needs only edma-\u003emembase. Add a membase field at the end\nof the event and use the new field for log output. Keep the existing\nfields for backward compatibility.","modified":"2026-09-17T03:47:20.387277862Z","published":"2026-09-16T10:33:07.292Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89994.json","cna_assigner":"Linux"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2a3801ae5c344473e648006c5b03a9216ac54a6a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2ea04dca8e627f722caa7a2037cfbae0257f3501"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d382aaf5fed38c6dd2e0cc710d97cb81d660ffa7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ef02cd3807f39ae1dbc924788d8fa6a85334c435"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89994.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89994"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"11102d0c343ba06ddd303f2503c0ce46d70052f2"},{"fixed":"ef02cd3807f39ae1dbc924788d8fa6a85334c435"},{"fixed":"d382aaf5fed38c6dd2e0cc710d97cb81d660ffa7"},{"fixed":"2a3801ae5c344473e648006c5b03a9216ac54a6a"},{"fixed":"2ea04dca8e627f722caa7a2037cfbae0257f3501"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89994.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.10.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.51"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89994.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}