cbcvebase.
CVE-2024-56719
published 2024-12-29

CVE-2024-56719: In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of tx_skbuff_dma[]'s members to be later in stmmac_tso_xmit(). The buf (dma cookie) and len stored in this structure are passed to dma_unmap_single() by stmmac_tx_clean(). The DMA API requires that the dma cookie passed to dma_unmap_single() is the same as the value returned from dma_map_single(). However, by moving the assignment later, this is not the case when priv->dma_cap.addr64 > 32 as "des" is offset by proto_hdr_len. This causes problems such as: dwc-eth-dwmac 2490000.ethernet eth0: Tx DMA map failed and with DMA_API_DEBUG enabled: DMA-API: dwc-eth-dwmac 2490000.ethernet: device driver tries to +free DMA memory it has not allocated [device address=0x000000ffffcf65c0] [size=66 bytes] Fix this by maintaining "des" as the original DMA cookie, and use tso_des to pass the offset DMA cookie to stmmac_tso_allocator(). Full details of the crashes can be found at: https://lore.kernel.org/all/[email protected]/ https://lore.kernel.org/all/klkzp5yn5kq5efgtrow6wbvnc46bcqfxs65nz3qy77ujr5turc@bwwhelz2l4dw/

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.8-1 (forky)linux 6.12.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 07c9c26e37542486e34d767505e842f48f29c3f6 < db3667c9bbfbbf5de98e6c9542f7e03fb5243286db3667c9bbfbbf5de98e6c9542f7e03fb5243286
linuxlinux>= 5.15.171 < 5.15.2095.15.209
linuxlinux>= 6.1.116 < 6.1.1676.1.167
linuxlinux>= 6.11.7 < 6.126.12
linuxlinux>= 6.6.60 < 6.6.686.6.68
linuxlinux>= 66600fac7a984dea4ae095411f644770b2561ede < 9d5dd7ccea1b46a9a7c6b3c2b9e5ed8864e185e29d5dd7ccea1b46a9a7c6b3c2b9e5ed8864e185e2
linuxlinux>= 66600fac7a984dea4ae095411f644770b2561ede < 4c49f38e20a57f8abaebdf95b369295b153d1f8e4c49f38e20a57f8abaebdf95b369295b153d1f8e
linuxlinux>= a3ff23f7c3f0e13f718900803e090fd3997d6bc9 < 6abcdc9a73274052a9e96a1926994ecf9aedad826abcdc9a73274052a9e96a1926994ecf9aedad82
linuxlinux>= ece593fc9c00741b682869d3f3dc584d37b7c9df < 05968b6dd0ffc65d7386608b11a11fb4fdfc9f3605968b6dd0ffc65d7386608b11a11fb4fdfc9f36
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 5.15.171 < 5.165.16
linuxlinux_kernel>= 6.1.116 < 6.26.2
linuxlinux_kernel>= 6.11.7 < 6.12.76.12.7
linuxlinux_kernel>= 6.6.60 < 6.6.686.6.68
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.