Answer in brief
CVE-2026-98243 records a Unknown severity vulnerability in dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=035219a760edb35ae9a9e96beba7f122e26a997b <a4db25b8949d6ff9c1a685a1273a015e8bab29db || >=035219a760edb35ae9a9e96beba7f122e26a997b <3ed11c671ff7ec58c8fd96410233c677df23f407 || 15ecfdf0ef6f6d874d0a26690d300857b39ebfd0 || >=7.1.5 <7.2 | a4db25b8949d6ff9c1a685a1273a015e8bab29db, 3ed11c671ff7ec58c8fd96410233c677df23f407, 7.2 |
| Linux/Linuxgeneric | 7.2 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 The patch "dma-buf: dma-fence: Fix potential NULL pointer dereference" changed the check to test for the ops pointer instead of the signaled bit to avoid a potential NULL dereference when the ops pointer has been cleared. The problem is now that the ops pointer is cleared only when neither the release nor the wait callback is implemented and this isn't true for a lot of dma_fence implementations yet. So those implementations lost the RCU protection after signaling of the returned string resulting in potential use after free. Add the signaling check additional to the ops pointer check so that we have both the protection against NULL dereference as well as the RCU protection after signaling for the returned string. v2: improve comments to note RCU protection and explain why we check both signaling state and ops pointer v3: some comment improvements suggested by Philip
Quoted source text, attributed separately from HOL analysis.