CVE-2024-26680
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
02/04/2024
Last modified:
17/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: atlantic: Fix DMA mapping for PTP hwts ring<br />
<br />
Function aq_ring_hwts_rx_alloc() maps extra AQ_CFG_RXDS_DEF bytes<br />
for PTP HWTS ring but then generic aq_ring_free() does not take this<br />
into account.<br />
Create and use a specific function to free HWTS ring to fix this<br />
issue.<br />
<br />
Trace:<br />
[ 215.351607] ------------[ cut here ]------------<br />
[ 215.351612] DMA-API: atlantic 0000:4b:00.0: device driver frees DMA memory with different size [device address=0x00000000fbdd0000] [map size=34816 bytes] [unmap size=32768 bytes]<br />
[ 215.351635] WARNING: CPU: 33 PID: 10759 at kernel/dma/debug.c:988 check_unmap+0xa6f/0x2360<br />
...<br />
[ 215.581176] Call Trace:<br />
[ 215.583632] <br />
[ 215.585745] ? show_trace_log_lvl+0x1c4/0x2df<br />
[ 215.590114] ? show_trace_log_lvl+0x1c4/0x2df<br />
[ 215.594497] ? debug_dma_free_coherent+0x196/0x210<br />
[ 215.599305] ? check_unmap+0xa6f/0x2360<br />
[ 215.603147] ? __warn+0xca/0x1d0<br />
[ 215.606391] ? check_unmap+0xa6f/0x2360<br />
[ 215.610237] ? report_bug+0x1ef/0x370<br />
[ 215.613921] ? handle_bug+0x3c/0x70<br />
[ 215.617423] ? exc_invalid_op+0x14/0x50<br />
[ 215.621269] ? asm_exc_invalid_op+0x16/0x20<br />
[ 215.625480] ? check_unmap+0xa6f/0x2360<br />
[ 215.629331] ? mark_lock.part.0+0xca/0xa40<br />
[ 215.633445] debug_dma_free_coherent+0x196/0x210<br />
[ 215.638079] ? __pfx_debug_dma_free_coherent+0x10/0x10<br />
[ 215.643242] ? slab_free_freelist_hook+0x11d/0x1d0<br />
[ 215.648060] dma_free_attrs+0x6d/0x130<br />
[ 215.651834] aq_ring_free+0x193/0x290 [atlantic]<br />
[ 215.656487] aq_ptp_ring_free+0x67/0x110 [atlantic]<br />
...<br />
[ 216.127540] ---[ end trace 6467e5964dd2640b ]---<br />
[ 216.132160] DMA-API: Mapped at:<br />
[ 216.132162] debug_dma_alloc_coherent+0x66/0x2f0<br />
[ 216.132165] dma_alloc_attrs+0xf5/0x1b0<br />
[ 216.132168] aq_ring_hwts_rx_alloc+0x150/0x1f0 [atlantic]<br />
[ 216.132193] aq_ptp_ring_alloc+0x1bb/0x540 [atlantic]<br />
[ 216.132213] aq_nic_init+0x4a1/0x760 [atlantic]
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 6.1.78 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.17 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/004fe5b7f59286a926a45e0cafc7870e9cdddd56
- https://git.kernel.org/stable/c/2e7d3b67630dfd8f178c41fa2217aa00e79a5887
- https://git.kernel.org/stable/c/466ceebe48cbba3f4506f165fca7111f9eb8bb12
- https://git.kernel.org/stable/c/e42e334c645575be5432adee224975d4f536fdb1
- https://git.kernel.org/stable/c/004fe5b7f59286a926a45e0cafc7870e9cdddd56
- https://git.kernel.org/stable/c/2e7d3b67630dfd8f178c41fa2217aa00e79a5887
- https://git.kernel.org/stable/c/466ceebe48cbba3f4506f165fca7111f9eb8bb12
- https://git.kernel.org/stable/c/e42e334c645575be5432adee224975d4f536fdb1



