---
id: CVE-2025-71221
title: 'dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()

  Add proper locking in mmp_pdma_residue() to prevent use-after-free when
  accessing descriptor list and des…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    3f0e0e2d9e752570041e95fd04635e2580097819
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    dfb5e05227745de43b7fd589721817a4337c970d
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    eba0c75670c022cb1f948600db972524bcfe8166
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    fc023b8fab057f0c910856ff36d3e12a30b7af4a
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    9f665b3c3d9a168410251f27a5d019b7bf93185c
  - >-
    Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 <
    a143545855bc2c6e1330f6f57ae375ac44af00a7
  - Linux 3.16
published: '2026-02-14'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:16.241Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-71221'
references:
  - url: 'https://git.kernel.org/stable/c/3f0e0e2d9e752570041e95fd04635e2580097819'
  - url: 'https://git.kernel.org/stable/c/dfb5e05227745de43b7fd589721817a4337c970d'
  - url: 'https://git.kernel.org/stable/c/eba0c75670c022cb1f948600db972524bcfe8166'
  - url: 'https://git.kernel.org/stable/c/fc023b8fab057f0c910856ff36d3e12a30b7af4a'
  - url: 'https://git.kernel.org/stable/c/9f665b3c3d9a168410251f27a5d019b7bf93185c'
  - url: 'https://git.kernel.org/stable/c/a143545855bc2c6e1330f6f57ae375ac44af00a7'
tags:
  - cve.org
epss: 0.001
epssPercentile: 0.00796
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()

Add proper locking in mmp_pdma_residue() to prevent use-after-free when
accessing descriptor list and descriptor contents.

The race occurs when multiple threads call tx_status() while the tasklet
on another CPU is freeing completed descriptors:

CPU 0                              CPU 1
-----                              -----
mmp_pdma_tx_status()
mmp_pdma_residue()
  -> NO LOCK held
     list_for_each_entry(sw, ..)
                                   DMA interrupt
                                   dma_do_tasklet()
                                     -> spin_lock(&desc_lock)
                                        list_move(sw->node, ...)
                                        spin_unlock(&desc_lock)
  |                                     dma_pool_free(sw) <- FREED!
  -> access sw->desc <- UAF!

This issue can be reproduced when running dmatest on the same channel with
multiple threads (threads_per_chan > 1).

Fix by protecting the chain_running list iteration and descriptor access
with the chan->desc_lock spinlock.

## Affected

- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < 3f0e0e2d9e752570041e95fd04635e2580097819`
- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < dfb5e05227745de43b7fd589721817a4337c970d`
- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < eba0c75670c022cb1f948600db972524bcfe8166`
- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < fc023b8fab057f0c910856ff36d3e12a30b7af4a`
- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < 9f665b3c3d9a168410251f27a5d019b7bf93185c`
- `Linux >= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < a143545855bc2c6e1330f6f57ae375ac44af00a7`
- `Linux 3.16`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
