CVE-2024-53127: Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
In the Linux kernel, the following vulnerability has been resolved:
Revert "mmc: dwmmc: Fix IDMAC operation with pages bigger than 4K"
The commit 8396c793ffdf ("mmc: dwmmc: Fix IDMAC operation with pages bigger than 4K") increased the maxreqsize, even for 4K pages, causing various issues: - Panic booting the kernel/rootfs from an SD card on Rockchip RK3566 - Panic booting the kernel/rootfs from an SD card on StarFive JH7100 - "swiotlb buffer is full" and data corruption on StarFive JH7110
At this stage no fix have been found, so it's probably better to just revert the change.
This reverts commit 8396c793ffdf28bb8aee7cfe0891080f8cab7890.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 8396c793ffdf28bb8aee7cfe0891080f8cab7890 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53127?
The severity of CVE-2024-53127 is classified as medium due to its potential impact on system stability.
How do I fix CVE-2024-53127?
To fix CVE-2024-53127, update the Linux kernel to versions beyond 4.20, 6.1.119, 6.6.63, or 6.11.10.
Which Linux kernel versions are affected by CVE-2024-53127?
CVE-2024-53127 affects Linux kernel versions between 4.19.322 and 4.20, 6.1.110 and 6.1.119, 6.6.51 and 6.6.63, and 6.11 and 6.11.10.
What types of systems are impacted by CVE-2024-53127?
CVE-2024-53127 impacts systems running the affected versions of the Linux kernel.
Who should be concerned about CVE-2024-53127?
System administrators and users running affected Linux kernel versions should be concerned about CVE-2024-53127.