{"apiVersion":"1.0","identifier":"CVE-2026-72476","description":"In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use after free In dma_release_channel(), check chan->device->privatecnt after call dma_chan_put(). However, dma_chan_put() call dma_device_put() which could release the last reference of the device if the DMA provider is already gone and hence free it. Fixes it by moving dma_chan_put() after the check.","publishedAt":"2026-08-15T06:22:21","lastModifiedAt":"2026-08-17T06:19:15","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72476","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00171,"riskScore":0.79,"affectedProduct":"linux","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72476","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72476","en":"https://www.redsauce.net/en/cves/CVE-2026-72476","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72476","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72476","de":"https://www.redsauce.net/de/cves/CVE-2026-72476","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72476","el":"https://www.redsauce.net/el/cves/CVE-2026-72476"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72476"}}