CVE-2024-40970: Avoid hw_desc array overrun in dw-axi-dmac

Published Jul 12, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Avoid hwdesc array overrun in dw-axi-dmac

I have a use case where nrbuffers = 3 and in which each descriptor is composed by 3 segments, resulting in the DMA channel descsallocated to be 9. Since axidescput() handles the hwdesc considering the descsallocated, this scenario would result in a kernel panic (hwdesc array will be overrun).

To fix this, the proposal is to add a new member to the axidmadesc structure, where we keep the number of allocated hwdescs (axidescalloc()) and use it in axidescput() to handle the hwdesc array correctly.

Additionally I propose to remove the axichanstartfirstqueued() call after completing the transfer, since it was identified that unbalance can occur (started descriptors can be interrupted and transfer ignored due to DMA channel not being enabled).

Affected Software

6 affected componentsFixes available
Linux Linux kernel<5.15.162
Linux Linux kernel>=5.16<6.1.96
Linux Linux kernel>=6.2<6.6.36
Linux Linux kernel>=6.7<6.9.7
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1

Event History

Jul 12, 2024
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityAffected Software
May 1, 2025
Data Sourced
via Ubuntu·06:16 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-40970?

CVE-2024-40970 has been classified with a medium severity due to the potential for array overrun in the DMA channel.

2

How do I fix CVE-2024-40970?

To mitigate CVE-2024-40970, upgrade the Linux kernel to version 6.1.123-1 or later.

3

Which versions of the Linux kernel are affected by CVE-2024-40970?

CVE-2024-40970 affects Linux kernel versions prior to 5.15.162, as well as several versions between 5.16 and 6.6.36.

4

What type of vulnerability is CVE-2024-40970?

CVE-2024-40970 is an array overrun vulnerability that affects the hw_desc array in the Linux kernel.

5

Is CVE-2024-40970 exploitable on all Linux distributions?

Exploitation of CVE-2024-40970 may vary across distributions but primarily affects those using the vulnerable Linux kernel versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203