CVE-2026-72147

Updated on 15 Aug 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: dw-edma-pcie: Reject devices without driver data

dw_edma_pcie_probe() treats the PCI device ID driver_data as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference.

Reject such matches before enabling the device.

Details

Affected packages:
linux @ 4.19.0 (+2 more)

Fixes