← Back to search

CVE-2026-89995

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
This flaw involves a return type mismatch in the `dma_direct_alloc_from_pool` function, leading to incorrect handling of `struct page *`. It matters because it could allow an attacker to manipulate memory allocations, potentially leading to privilege escalation or other severe consequences.
Exploitability
Exploitation requires specific kernel context and understanding of DMA memory management. Precondition is the presence of a vulnerable kernel version and potential for an attacker to interact with DMA operations.
Blast radius
If exploited, the impact could be significant, potentially allowing an attacker to gain elevated privileges or cause system instability.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 5b138c534fda or later.
kernelmemoryprivilege-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: dma-direct: return struct page from dma_direct_alloc_from_pool() Commit 5b138c534fda ("dma-direct: factor out a dma_direct_alloc_from_pool helper") changed dma_direct_alloc_from_pool() to return the CPU address from dma_alloc_from_pool(). That fits dma_direct_alloc(), but dma_direct_alloc_pages() also uses the helper and expects a struct page *. Fix this by making dma_direct_alloc_from_pool() return the struct page * again, and pass the CPU address back through an out-parameter for the dma_direct_alloc() caller.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.