CVE-2026-72149: dmaengine: tegra: Fix burst size calculation
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: tegra: Fix burst size calculation
Currently, the Tegra GPC DMA hardware requires the transfer length to be a multiple of the max burst size configured for the channel. When a client requests a transfer where the length is not evenly divisible by the configured max burst size, the DMA hangs with partial burst at the end.
Fix this by reducing the burst size to the largest power-of-2 value that evenly divides the transfer length. For example, a 40-byte transfer with a 16-byte max burst will now use an 8-byte burst (40 / 8 = 5 complete bursts) instead of causing a hang.
This issue was observed with the PL011 UART driver where TX DMA transfers of arbitrary lengths were stuck.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72149?
CVE-2026-72149 has a risk classification of 24.
How do I fix CVE-2026-72149?
To fix CVE-2026-72149, update your Linux kernel to the latest version where the vulnerability is resolved.
What is the impact of CVE-2026-72149?
CVE-2026-72149 affects DMA transfer requests that do not meet the required length constraints, potentially leading to data handling errors.
Is CVE-2026-72149 a local or remote vulnerability?
CVE-2026-72149 can be exploited locally, as it involves driver issues in the Linux kernel related to DMA operations.
Which versions of Linux are affected by CVE-2026-72149?
CVE-2026-72149 affects specific versions of the Linux kernel that utilize Tegra GPC DMA hardware.