CVE-2026-80884: ntb: Store original DMA address for future release
Published Sep 4, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
ntb: Store original DMA address for future release
The DMA API requires that dmafreeattrs receive the exact dmahandle originally returned by the allocation function. Do not modify it.
Affected Software
1 affected component
Linux Kernel
Event History
Sep 4, 2026
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
What condition triggers the incorrect DMA release?
The issue occurs when the NTB code modifies a DMA handle after allocation and later passes that modified value to dma_free_attrs instead of the exact handle originally returned by the DMA allocation API.
2
What should a fix preserve in this code path?
The original DMA address returned by the allocation function must be stored and passed unchanged to dma_free_attrs when the allocation is released.