HomeDefectsLIN1024-32486
Fixed

LIN1024-32486 : Security Advisory - linux - CVE-2026-89994

Created: Oct 7, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.24.33.2
Fix Version: 10.24.33.5
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  dmaengine: fsl-edma: tracing: no ptr dereference during log output  The fsl edma events store a pointer to a struct fsl_edma_engine in the ringbuffer and dereference it when a log entry is printed. At this time, the pointer may no longer be valid.  Event injection can be used to trigger a crash:  $ cd /sys/kernel/tracing $ echo 'value = 0' > events/fsl_edma/edma_writeb/inject $ cat trace  The log output needs only edma->membase. Add a membase field at the end of the event and use the new field for log output. Keep the existing fields for backward compatibility.