{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-46716", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-09-11T15:12:18.254Z", "datePublished": "2024-09-18T06:32:16.084Z", "dateUpdated": "2026-08-05T11:38:07.411Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:38:07.411Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor\n\nRemove list_del call in msgdma_chan_desc_cleanup, this should be the role\nof msgdma_free_descriptor. In consequence replace list_add_tail with\nlist_move_tail in msgdma_free_descriptor.\n\nThis fixes the path:\n msgdma_free_chan_resources -> msgdma_free_descriptors ->\n msgdma_free_desc_list -> msgdma_free_descriptor\n\nwhich does not correctly free the descriptors as first nodes were not\nremoved from the list." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The Altera/Intel mSGDMA is a memory-mapped platform DMA controller on SoC-FPGA systems; the vulnerable free/alloc path is reached only through local dmaengine client activity (device-node open/close driving dma_chan_get/dma_chan_put), never from remote or adjacent-network input.\nAC:L - No race or uncontrollable precondition is involved — submitting a descriptor and then releasing the channel deterministically leaves pending_list non-empty at msgdma_free_descriptors() time, guaranteeing the list corruption and the dangling list heads that survive into the next channel allocation.\nPR:L - An unprivileged local user with access to the FPGA-fabric peripheral's device node (routinely group-accessible on industrial/embedded SoC-FPGA deployments) can drive the submit/release/re-acquire cycle that triggers the bug; no root or CAP_SYS_ADMIN gate exists on the dmaengine descriptor path.\nUI:N - The attacker performs the entire sequence itself — open, prep/submit, close, reopen, submit — with no victim action, file to open, or filesystem to mount required.\nS:U - The corruption and its consequences remain within the kernel's own security authority; the DMA programming is issued by the kernel on its own behalf and no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The dangling descriptor pointers are read back after kfree(mdev->sw_desq), and msgdma_copy_one() feeds their hw_desc source/destination addresses straight to the hardware DMA engine, allowing arbitrary physical memory to be read out to the FPGA peripheral in addition to the general UAF read of reallocated kernel objects.\nI:H - The stale list heads give a UAF write primitive (list_add_tail through pending_list.prev), an OOB write into struct msgdma_device via the unchecked list_first_entry() in msgdma_get_descriptor(), and an indirect call through a callback function pointer loaded from freed memory in msgdma_chan_desc_cleanup() — all usable for control-flow hijacking.\nA:H - Traversing the cross-linked pending/active/done lists into freed memory reliably produces list-corruption oopses, and the hardware DMA engine is programmed from garbage descriptors, crashing or hanging the system." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/dma/altera-msgdma.c" ], "versions": [ { "version": "a85c6f1b2921cbd2f54666a52804f407c4a064fe", "lessThan": "a3480e59fdbe5585d2d1eff0bed7671583acf725", "status": "affected", "versionType": "git" }, { "version": "a85c6f1b2921cbd2f54666a52804f407c4a064fe", "lessThan": "20bf2920a869f9dbda0ef8c94c87d1901a64a716", "status": "affected", "versionType": "git" }, { "version": "a85c6f1b2921cbd2f54666a52804f407c4a064fe", "lessThan": "db67686676c7becc1910bf1d6d51505876821863", "status": "affected", "versionType": "git" }, { "version": "a85c6f1b2921cbd2f54666a52804f407c4a064fe", "lessThan": "54e4ada1a4206f878e345ae01cf37347d803d1b1", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/dma/altera-msgdma.c" ], "versions": [ { "version": "4.14", "status": "affected" }, { "version": "0", "lessThan": "4.14", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.109", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.50", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.9", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.1.109" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.6.50" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.10.9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/a3480e59fdbe5585d2d1eff0bed7671583acf725" }, { "url": "https://git.kernel.org/stable/c/20bf2920a869f9dbda0ef8c94c87d1901a64a716" }, { "url": "https://git.kernel.org/stable/c/db67686676c7becc1910bf1d6d51505876821863" }, { "url": "https://git.kernel.org/stable/c/54e4ada1a4206f878e345ae01cf37347d803d1b1" } ], "title": "dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-09-29T14:58:09.271369Z", "id": "CVE-2024-46716", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-29T14:58:23.448Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:16:48.183Z" } } ] } }