CVE-2024-35990: dma: xilinx_dpdma: Fix locking
Published May 20, 2024
·Updated
dma: xilinxdpdma: Fix locking
Affected Software
10 affected componentsFixes available
Linux Linux kernel>=5.9<5.10.216
Linux Linux kernel>=5.11<5.15.158
Linux Linux kernel>=5.16<6.1.90
Linux Linux kernel>=6.2<6.6.30
Linux Linux kernel>=6.7<6.8.9
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Microsoft cbl2 kernel 5.15.153.1-2
Microsoft azl3 kernel 6.6.35.1-4
Microsoft cbl2 kernel 5.15.158.1-1
Microsoft azl3 kernel 6.6.29.1-5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
May 20, 2024
CVE Published
via MITRE·09:47 AM
Data Sourced
via MITRE·09:47 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jul 15, 2024
Data Sourced
via Launchpad·05:02 PM
Description
May 1, 2025
Data Sourced
via Ubuntu·12:26 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35990?
The severity of CVE-2024-35990 is moderate due to its potential to cause locking issues in the Linux kernel.
2
How do I fix CVE-2024-35990?
To fix CVE-2024-35990, you should upgrade to the corrected versions listed, such as 5.10.223-1 or 6.1.123-1.
3
What are the affected versions of the Linux kernel for CVE-2024-35990?
CVE-2024-35990 affects Linux kernel versions from 5.9 to 6.6.30.
4
What is the nature of the vulnerability in CVE-2024-35990?
CVE-2024-35990 involves inadequate locking in the Xilinx DPDMA driver, leading to potential concurrency issues.
5
Is CVE-2024-35990 a local or remote vulnerability?
CVE-2024-35990 is considered a local vulnerability as it requires local access to the system.