{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  dmaengine: Fix device kref underflow in dma_chan_put()  dma_chan_get() takes chan-\u003edevice-\u003eref only on the slow path:  \t/* no kref on fast path */ \tif (chan-\u003eclient_count) { \t\t__module_get(owner); \t\tchan-\u003eclient_count++; \t\treturn 0; \t} \tif (!try_module_get(owner)) \t\treturn -ENODEV; \tif (!dma_device_get(chan-\u003edevice)) { // calls kref_get_unless_zero()  dma_chan_put() drops the ref unconditionally, so every fast-path get/put pair drops one extra device reference.  The bug fires when two conditions hold together: a non-private provider has a persistent client holding chan-\u003eclient_count \u003e 0 and another client cycles dmaengine_get()/dmaengine_put(). When the kref hits zero, the subsequent dma_find_channel() returns NULL even though the provider module is still loaded.  Fix this by dropping device-\u003eref only on the last put, matching the single slow-path get.",
  "id": "DEBIAN-CVE-2026-98344",
  "modified": "2026-10-07T04:47:42.138146712Z",
  "published": "2026-10-06T09:18:27.323Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98344"
    }
  ],
  "upstream": [
    "CVE-2026-98344"
  ]
}