{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-27408","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-25T13:47:42.682Z","datePublished":"2024-05-17T11:50:36.208Z","dateUpdated":"2026-08-05T11:29:38.896Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:29:38.896Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup\n\nThe Linked list element and pointer are not stored in the same memory as\nthe eDMA controller register. If the doorbell register is toggled before\nthe full write of the linked list a race condition error will occur.\nIn remote setup we can only use a readl to the memory to assure the full\nwrite has occurred."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable sequence is reached only through the local dmaengine client API (`dma_async_issue_pending()` → `dw_edma_device_issue_pending()` → `dw_edma_v0_core_start()`), i.e. via a device node or in-kernel client on the host driving the remote eDMA. There is no network- or packet-facing path into drivers/dma/dw-edma/.\nAC:L - An attacker able to submit transfers can repeat them indefinitely at no cost and can widen the window at will by building large scatter-gather lists, since every chunk re-writes the LL and rings the doorbell again — and per the commit, on affected remote setups the unordered doorbell simply races the LL writes rather than requiring an unusual condition.\nPR:L - No capability check exists on the path — the dmaengine core imposes none, so an unprivileged local account with ordinary access to a client device node backed by these eDMA channels is sufficient to issue the transfers that ring the doorbell.\nUI:N - The attacker drives the entire submit/complete cycle on its own; no action by another user or administrator is needed, and an already-bound dw-edma-pcie device is system configuration rather than victim interaction.\nS:U - The corrupted transfers act on host memory already within the DMA mapping the kernel authorized for this device, all under the same kernel security authority; no IOMMU, VM, or sandbox boundary is bypassed.\nC:H - A torn descriptor makes the engine read from the previous chunk's SAR while writing to the new DAR, and a not-yet-landed LLP terminator lets it walk past the LL region and follow arbitrary BAR contents as descriptors, so effectively arbitrary host memory can be sourced and shipped to the remote endpoint or into a buffer the attacker reads back.\nI:H - The same stale or run-away descriptors give the PCIe engine a write with attacker-influenceable destination and length into host kernel-mapped memory — a memory-corruption write primitive, not merely wrong data in the intended buffer.\nA:H - DMA into unintended kernel memory reliably produces corruption and oops/panic, and the malformed descriptor walk also raises linked-list errors and abort interrupts that stall the channel and hang clients waiting on completion."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/dw-edma/dw-edma-v0-core.c"],"versions":[{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3","status":"affected","versionType":"git"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"f396b4df27cfe01a99f4b41f584c49e56477be3a","status":"affected","versionType":"git"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"bbcc1c83f343e580c3aa1f2a8593343bf7b55bba","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dma/dw-edma/dw-edma-v0-core.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"6.6.21","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.9","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.6.21"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.7.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3"},{"url":"https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a"},{"url":"https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba"}],"title":"dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-27408","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-05-21T16:00:32.783313Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:46:41.685Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:34:52.272Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba","tags":["x_transferred"]}]}]}}