CVE-2024-46852: dma-buf: heaps: Fix off-by-one in CMA heap fault handler
dma-buf: heaps: Fix off-by-one in CMA heap fault handler
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Compensating control
Limit use of mremap/mmap operations that could create a CMA heap mapping larger than the underlying buffer size until the off-by-one bug in the CMA heap fault handler is fixed in the Linux kernel.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46852?
CVE-2024-46852 has not been assigned a CVSS score yet, but it addresses a critical off-by-one error in the Linux kernel's CMA heap fault handler.
How do I fix CVE-2024-46852?
To mitigate CVE-2024-46852, update your Linux kernel to a patched version such as 5.10.223-1, 5.10.226-1, 6.1.123-1, or 6.12.11-1.
Which Linux kernel versions are affected by CVE-2024-46852?
CVE-2024-46852 affects Linux kernel versions between 5.11 and 6.6.52, as well as several release candidates of 6.11.
What does the CVE-2024-46852 vulnerability impact?
CVE-2024-46852 can potentially allow an attacker to exploit memory handling issues in kernel space, leading to privilege escalation.
Is there a workaround for CVE-2024-46852?
Currently, the recommended resolution for CVE-2024-46852 is to apply the latest security patches rather than relying on workarounds.