CVE-2024-40956
Published: Jul 12, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list Use list_for_each_entry_safe() to allow iterating through the list and deleting the entry in the iteration process. The descriptor is freed via idxd_desc_complete() and there's a slight chance may cause issue for the list iterator when the descriptor is reused by another thread without it being deleted from the list.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 16e19e11228ba660d9e322035635e7dcf160d5c2 - < 1b08bf5a17c66ab7dbb628df5344da53c8e7ab33affected 16e19e11228ba660d9e322035635e7dcf160d5c2 - < 83163667d881100a485b6c2daa30301b7f68d9b5affected 16e19e11228ba660d9e322035635e7dcf160d5c2 - < faa35db78b058a2ab6e074ee283f69fa398c36a8affected 16e19e11228ba660d9e322035635e7dcf160d5c2 - < a14968921486793f2a956086895c3793761309ddaffected 16e19e11228ba660d9e322035635e7dcf160d5c2 - < e3215deca4520773cd2b155bed164c12365149a7 |
Linux | Linux | affected 5.11unaffected 0 - < 5.11unaffected 5.15.162 - <= 5.15.*unaffected 6.1.96 - <= 6.1.*unaffected 6.6.36 - <= 6.6.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now