Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2024-53127— Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"

EPSS 0.01% · P3

Affected Version Matrix 26

VendorProductVersion RangeStatus
LinuxLinux32bd402f6760d57127d58a9888553b2db574bba6< 00bff71745bc3583bd5ca59be91e0ee1d27f1944affected
b9ee16a20d9976686185d7e59cd006c328b6a1e0< 47693ba35bccaa16efa465159a1c12d78258349eaffected
2793f423893579b35dc1fc24dd7c1ce58fa0345a< 938c13740f8b555986e53c0fcbaf00dcd1fabd4caffected
9d715a234dd8f01af970b78ae2144a2fd3ead21c< f701eb601470bfc0a551913ce5f6ebaa770f0ce0affected
373f8f5b087f010dddae3306a79c6fdd5c2f8953< 8f9416147d7ed414109d3501f1cb3d7a1735b25aaffected
5b4bf3948875064a9adcda4b52b59e0520a8c576< 56de724c58c07a7ca3aac027cfd2ccb184ed9e4eaffected
8396c793ffdf28bb8aee7cfe0891080f8cab7890< a4685366f07448420badb710ff5c12aaaadf63adaffected
8396c793ffdf28bb8aee7cfe0891080f8cab7890< 1635e407a4a64d08a8517ac59ca14ad4fc785e75affected
… +18 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-53127

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" The commit 8396c793ffdf ("mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K") increased the max_req_size, even for 4K pages, causing various issues: - Panic booting the kernel/rootfs from an SD card on Rockchip RK3566 - Panic booting the kernel/rootfs from an SD card on StarFive JH7100 - "swiotlb buffer is full" and data corruption on StarFive JH7110 At this stage no fix have been found, so it's probably better to just revert the change. This reverts commit 8396c793ffdf28bb8aee7cfe0891080f8cab7890.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mmc驱动中由于增大max_req_size导致的各种问题,包括在Rockchip RK3566和StarFive JH7100上从SD卡启动时的内核崩溃,以及StarFive JH7110上的数据损坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 32bd402f6760d57127d58a9888553b2db574bba6 ~ 00bff71745bc3583bd5ca59be91e0ee1d27f1944 -
LinuxLinux 6.11 -

II. Public POCs for CVE-2024-53127

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-53127

登录查看更多情报信息。

Patches & Fixes for CVE-2024-53127 (8)

Same Patch Batch · Linux · 2024-12-04 · 16 CVEs total

CVE-2024-53125bpf: sync_linked_regs() must preserve subreg_def
CVE-2024-53126vdpa: solidrun: Fix UB bug with devres
CVE-2024-53128sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers
CVE-2024-53129drm/rockchip: vop: Fix a dereferenced before check warning
CVE-2024-53130nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
CVE-2024-53131nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
CVE-2024-53132drm/xe/oa: Fix "Missing outer runtime PM protection" warning
CVE-2024-53133drm/amd/display: Handle dml allocation failure to avoid crash
CVE-2024-53134pmdomain: imx93-blk-ctrl: correct remove path
CVE-2024-53135KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
CVE-2024-53136mm: revert "mm: shmem: fix data-race in shmem_getattr()"
CVE-2024-53138net/mlx5e: kTLS, Fix incorrect page refcounting
CVE-2024-53137ARM: fix cacheflush with PAN
CVE-2024-53139sctp: fix possible UAF in sctp_v6_available()
CVE-2024-53140netlink: terminate outstanding dump on socket close

IV. Related Vulnerabilities

V. Comments for CVE-2024-53127

No comments yet


Leave a comment