CVE Database
/

CVE-2024-40956

Back to search

CVE-2024-40956

Published: Jul 12, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list Use list_for_each_entry_safe() to allow iterating through the list and deleting the entry in the iteration process. The descriptor is freed via idxd_desc_complete() and there's a slight chance may cause issue for the list iterator when the descriptor is reused by another thread without it being deleted from the list.

VendorProductVersions

Linux

Linux

affected
16e19e11228ba660d9e322035635e7dcf160d5c2 - < 1b08bf5a17c66ab7dbb628df5344da53c8e7ab33
affected
16e19e11228ba660d9e322035635e7dcf160d5c2 - < 83163667d881100a485b6c2daa30301b7f68d9b5
affected
16e19e11228ba660d9e322035635e7dcf160d5c2 - < faa35db78b058a2ab6e074ee283f69fa398c36a8
affected
16e19e11228ba660d9e322035635e7dcf160d5c2 - < a14968921486793f2a956086895c3793761309dd
affected
16e19e11228ba660d9e322035635e7dcf160d5c2 - < e3215deca4520773cd2b155bed164c12365149a7

Linux

Linux

affected
5.11
unaffected
0 - < 5.11
unaffected
5.15.162 - <= 5.15.*
unaffected
6.1.96 - <= 6.1.*
unaffected
6.6.36 - <= 6.6.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now