CVE-2024-27408

MEDIUM

Linux Kernel 5.3-6.6.20, 6.7.0-6.7.8 - Race Condition in eDMA Controller Register Write

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.

Scores

CVSS v3 4.7
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (12)
linux/Kernel 5.3.0 - 6.6.21linux
linux/Kernel 6.7.0 - 6.7.9linux
Linux/Linux < 5.3
Linux/Linux 5.3
Linux/Linux 6.6.21 - 6.6.*
Linux/Linux 6.7.9 - 6.7.*
Linux/Linux 6.8
Linux/Linux 7e4b8a4fbe2cecab0959e862604803d063f50029 - bbcc1c83f343e580c3aa1f2a8593343bf7b55bba
Linux/Linux 7e4b8a4fbe2cecab0959e862604803d063f50029 - d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3
Linux/Linux 7e4b8a4fbe2cecab0959e862604803d063f50029 - f396b4df27cfe01a99f4b41f584c49e56477be3a
... and 2 more
Published May 17, 2024
Tracked Since Feb 18, 2026