Executive brief
A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash. The issue occurs when the system incorrectly handles the release of memory used for hardware communication, potentially leading to internal data corruption. This primarily impacts system stability and availability.
Technical details
A race condition exists in dmam_free_coherent() due to an incorrect call order between dma_free_coherent() and devres_destroy(). In the vulnerable versions, dma_free_coherent() is called first, making the virtual address (vaddr) available for immediate reuse. If a concurrent task allocates the same vaddr and adds it to the devres list before the original task calls devres_destroy(), the kernel may destroy the wrong devres entry. This triggers a WARN_ON in dmam_match and can lead to resource management errors. The fix reorders the calls to ensure the devres entry is destroyed before the DMA allocation is freed.
Affected products
- Linux Linux kernel 2.6.21 to 4.19.320, 4.20 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.103, 6.2 to 6.6.44, 6.7 to 6.10.3
Timeline
- 2024-08-17: disclosed
- 2024-08-17: advisory
- 2024-07-19: patched: Initial patch in mainline kernel tree.
References
- https://git.kernel.org/stable/c/1fe97f68fce1ba24bf823bfb0eb0956003473130
- https://git.kernel.org/stable/c/22094f5f52e7bc16c5bf9613365049383650b02e
- https://git.kernel.org/stable/c/257193083e8f43907e99ea633820fc2b3bcd24c7
- https://git.kernel.org/stable/c/28e8b7406d3a1f5329a03aa25a43aa28e087cb20
- https://git.kernel.org/stable/c/2f7bbdc744f2e7051d1cb47c8e082162df1923c9
- https://git.kernel.org/stable/c/87b34c8c94e29fa01d744e5147697f592998d954
- https://git.kernel.org/stable/c/f993a4baf6b622232e4c190d34c220179e5d61eb