Junglewise Threat Intelligence

CVE-2024-26787: Linux Kernel mmci DMA mapping leak in STM32 SDMMC driver

CVE-2024-26787 · Severity: medium · CVSS 5.5 · Published 2024-04-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MMC (Multimedia Card) driver for STMicroelectronics STM32 devices could lead to system instability or a denial of service. The issue stems from improper memory management during data transfers, where the system fails to correctly release memory mappings if an error occurs. This can lead to memory leaks and overlapping memory assignments, potentially causing the system to crash or behave unpredictably during storage operations.

Technical details

A resource management vulnerability exists in the Linux kernel's mmci host driver (drivers/mmc/host/mmci_stm32_sdmmc.c) specifically affecting the STM32 SDMMC variant. The root cause is an imbalance between dma_map_sg and dma_unmap_sg calls; when an error occurs in the mmci_cmd_irq function, the driver calls mmci_dma_error, but the STM32 variant lacked a corresponding dma_error implementation to perform the necessary unmapping. This results in leaked DMA mappings and 'cacheline tracking EEXIST' warnings when overlapping mappings are attempted. An attacker with local access could potentially exploit this to cause a kernel panic or exhaustion of DMA resources. The fix introduces a proper sdmmc_idma_error handler to ensure dma_unmap_sg is called during error conditions.

Affected products

  • Linux Linux Kernel 4.20 to 5.10.213, 5.11 to 5.15.152, 5.16 to 6.1.81, 6.2 to 6.6.21, 6.7 to 6.7.9

Timeline

  • 2024-02-07: other: Initial patch submitted by developer
  • 2024-03-15: patched: Patch committed to stable kernel trees
  • 2024-04-04: advisory: CVE published by NVD

References

Related threats