Executive Summary

Informations
Name CVE-2024-44949 First vendor Publication 2024-09-04
Vendor Cve Last vendor Modification 2025-01-24

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7.8
Base Score 7.8 Environmental Score 7.8
impact SubScore 5.9 Temporal Score 7.8
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

parisc: fix a possible DMA corruption

ARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be possible that two unrelated 16-byte allocations share a cache line. If one of these allocations is written using DMA and the other is written using cached write, the value that was written with DMA may be corrupted.

This commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 - that's the largest possible cache line size.

As different parisc microarchitectures have different cache line size, we define arch_slab_minalign(), cache_line_size() and dma_get_cache_alignment() so that the kernel may tune slab cache parameters dynamically, based on the detected cache line size.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44949

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3670

Sources (Detail)

https://git.kernel.org/stable/c/00baca74fb5879e5f9034b6156671301f500f8ee
https://git.kernel.org/stable/c/533de2f470baac40d3bf622fe631f15231a03c9f
https://git.kernel.org/stable/c/642a0b7453daff0295310774016fcb56d1f5bc7f
https://git.kernel.org/stable/c/7ae04ba36b381bffe2471eff3a93edced843240f
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
Date Informations
2025-03-29 03:39:55
  • Multiple Updates
2025-03-28 13:44:27
  • Multiple Updates
2025-03-28 03:18:07
  • Multiple Updates
2025-03-19 03:13:29
  • Multiple Updates
2025-03-18 03:26:25
  • Multiple Updates
2025-03-14 03:13:42
  • Multiple Updates
2025-03-06 14:10:14
  • Multiple Updates
2025-02-22 03:23:47
  • Multiple Updates
2025-01-24 21:20:40
  • Multiple Updates
2025-01-08 03:04:50
  • Multiple Updates
2025-01-07 03:04:23
  • Multiple Updates
2024-12-24 21:20:43
  • Multiple Updates
2024-12-20 00:20:39
  • Multiple Updates
2024-12-15 00:20:42
  • Multiple Updates
2024-12-12 03:05:57
  • Multiple Updates
2024-12-02 13:20:44
  • Multiple Updates
2024-11-23 03:02:58
  • Multiple Updates
2024-11-22 03:01:09
  • Multiple Updates
2024-11-20 02:59:29
  • Multiple Updates
2024-11-14 02:59:47
  • Multiple Updates
2024-11-09 02:59:47
  • Multiple Updates
2024-10-26 02:57:10
  • Multiple Updates
2024-10-25 02:59:03
  • Multiple Updates
2024-10-23 02:58:15
  • Multiple Updates
2024-10-09 17:27:37
  • Multiple Updates
2024-09-05 17:27:25
  • Multiple Updates
2024-09-05 00:27:26
  • First insertion