CVE-2026-72148
Race condition in Linux dw-edma DMA driver may cause kernel crashes and data corruption.
Is CVE-2026-72148 being exploited?
Not confirmed. CVE-2026-72148 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.33% probability of exploitation in the next 30 days.
How severe is CVE-2026-72148?
CVE-2026-72148 is rated High. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72148?
Yes. A fix has been recorded for CVE-2026-72148. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72148 affect?
CVE-2026-72148 affects Linux kernel (dmaengine dw-edma driver), Embedded devices/SoCs using Synopsys DesignWare EDMA, Devices with dw-edma enabled kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72148?
Apply kernel update containing dw-edma spinlock fix and reboot affected systems.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Non-atomic updates to shared DMA registers can cause race conditions leading to kernel crash, DMA data corruption or device malfunction; may enable local DoS and risk of memory-corruption escalation.
Patch when possible
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 3989b4775bc2cdbdb4ddc4b1d2420a82b40913f2
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < f60c7463d44fbc1585d247d0bd6976f7a1099472
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 2247cc25a91fb1b5b86586ed55fdd5b725a7477c
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 3ee0f478bb29b4ee892b178179a9a76ddd194149
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 21a9834f56d6249aaa6ca7c2d8c182d66c48c3e1
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < ddbc4a8a4fe296f1fa2e59f7d176fc7c773df640
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 1553ca96e9df158d8f37137cf4bf5fb0dc981d94
- affected>= 7e4b8a4fbe2cecab0959e862604803d063f50029 and < 8ffba0171c6bbce5f093c6dba5a02c0805b31203
- affected5.3
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.