CVE-2026-98344: dmaengine: Fix device kref underflow in dma_chan_put()
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: Fix device kref underflow in dmachanput()
dmachanget() takes chan->device->ref only on the slow path:
/ no kref on fast path / if (chan->clientcount) { moduleget(owner); chan->clientcount++; return 0; } if (!trymoduleget(owner)) return -ENODEV; if (!dmadeviceget(chan->device)) { // calls krefgetunlesszero()
dmachanput() drops the ref unconditionally, so every fast-path get/put pair drops one extra device reference.
The bug fires when two conditions hold together: a non-private provider has a persistent client holding chan->clientcount > 0 and another client cycles dmaengineget()/dmaengineput(). When the kref hits zero, the subsequent dmafindchannel() returns NULL even though the provider module is still loaded.
Fix this by dropping device->ref only on the last put, matching the single slow-path get.