CVE-2024-46716

In the Linux kernel, the following vulnerability has been resolved: dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor Remove list_del call in msgdma_chan_desc_cleanup, this should be the role of msgdma_free_descriptor. In consequence replace list_add_tail with list_move_tail in msgdma_free_descriptor. This fixes the path: msgdma_free_chan_resources -> msgdma_free_descriptors -> msgdma_free_desc_list -> msgdma_free_descriptor which does not correctly free the descriptors as first nodes were not removed from the list.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

07 Oct 2025, 18:08

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/20bf2920a869f9dbda0ef8c94c87d1901a64a716 - () https://git.kernel.org/stable/c/20bf2920a869f9dbda0ef8c94c87d1901a64a716 - Patch
References () https://git.kernel.org/stable/c/54e4ada1a4206f878e345ae01cf37347d803d1b1 - () https://git.kernel.org/stable/c/54e4ada1a4206f878e345ae01cf37347d803d1b1 - Patch
References () https://git.kernel.org/stable/c/a3480e59fdbe5585d2d1eff0bed7671583acf725 - () https://git.kernel.org/stable/c/a3480e59fdbe5585d2d1eff0bed7671583acf725 - Patch
References () https://git.kernel.org/stable/c/db67686676c7becc1910bf1d6d51505876821863 - () https://git.kernel.org/stable/c/db67686676c7becc1910bf1d6d51505876821863 - Patch

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: dmaengine: altera-msgdma: liberar correctamente el descriptor en msgdma_free_descriptor Eliminar la llamada list_del en msgdma_chan_desc_cleanup, esta debería ser la función de msgdma_free_descriptor. En consecuencia, reemplace list_add_tail con list_move_tail en msgdma_free_descriptor. Esto corrige la ruta: msgdma_free_chan_resources -> msgdma_free_descriptors -> msgdma_free_desc_list -> msgdma_free_descriptor que no libera correctamente los descriptores ya que los primeros nodos no se eliminaron de la lista.

18 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 07:15

Updated : 2025-10-07 18:08


NVD link : CVE-2024-46716

Mitre link : CVE-2024-46716

CVE.ORG link : CVE-2024-46716


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free