{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()  When dma_device_put() drops the last reference on chan-\u003edevice-\u003eref, dma_device_release() runs and may free the dma_device along with its channels.  dma_chan_put() then still reads chan-\u003edevice-\u003eowner via dma_chan_to_owner() for the trailing module_put(). KASAN catches it:  \tslab-use-after-free in dma_chan_put+0x3e6/0x4c0 \tRead of size 8 by task insmod/6319 \tFreed by task 6319: \t  kfree+0x225/0x470 \t  dma_chan_put+0x395/0x4c0 \t  dmaengine_put+0xf8/0x160  Cache the module owner in dma_chan_put() before the put so the trailing module_put() does not need chan-\u003edevice.",
  "id": "DEBIAN-CVE-2026-98343",
  "modified": "2026-10-07T04:47:40.580222517Z",
  "published": "2026-10-06T09:18:27.163Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98343"
    }
  ],
  "upstream": [
    "CVE-2026-98343"
  ]
}