cbcvebase.
CVE-2024-50101
published 2024-11-05

CVE-2024-50101: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices Previously, the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices Previously, the domain_context_clear() function incorrectly called pci_for_each_dma_alias() to set up context entries for non-PCI devices. This could lead to kernel hangs or other unexpected behavior. Add a check to only call pci_for_each_dma_alias() for PCI devices. For non-PCI devices, domain_context_clear_one() is called directly.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 48f2183a4f9d3540fc5cfc8f8451621ee92c09f8 < fe2e0b6cd00abea3efac66de1da22d844364c1b0fe2e0b6cd00abea3efac66de1da22d844364c1b0
linuxlinux>= 5.15.142 < 5.15.1695.15.169
linuxlinux>= 59862b869275c27beb25cda2054b59a8b5d04970 < cbfa3a83eba05240ce37839ed48280a05e8e8f6ccbfa3a83eba05240ce37839ed48280a05e8e8f6c
linuxlinux>= 6.1.66 < 6.1.1146.1.114
linuxlinux>= 6.6.5 < 6.6.586.6.58
linuxlinux>= 9807860f6ad446459d0446550cf4a2dc23bbee6c < 0bd9a30c22afb5da203386b811ec31429d2caa780bd9a30c22afb5da203386b811ec31429d2caa78
linuxlinux>= 9a16ab9d640274b20813d2d17475e18d3e99d834 < 04d6826ba7ba81213422276e96c90c6565169e1c04d6826ba7ba81213422276e96c90c6565169e1c
linuxlinux>= 9a16ab9d640274b20813d2d17475e18d3e99d834 < 6e02a277f1db24fa039e23783c8921c7b0e5b1b36e02a277f1db24fa039e23783c8921c7b0e5b1b3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.15.142 < 5.15.1695.15.169
linuxlinux_kernel>= 5.16 < 6.1.1146.1.114
linuxlinux_kernel>= 6.2 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.