CVE-2024-43877 (GCVE-0-2024-43877)
Vulnerability from cvelistv5
Published
2024-08-21 00:06
Modified
2026-08-05 11:36
Summary
In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In case DMA fails, 'dma->SG_length' is 0. This value is later used to access 'dma->SGarray[dma->SG_length - 1]', which will cause out of bounds access. Add check to return early on invalid value. Adjust warnings accordingly. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Impacted products
Vendor Product Version
Linux Linux Version: 4551236b55e80b2c1720b10b77e9400118b2339e
Version: 66c8a83bf1de2eb3eea4734c7eda22255a965f11
Version: 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1
Version: 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1
Version: 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1
Version: 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1
Version: 1b00b7335000c0e107f774cc8ee4d5340f824f28
Version: 5.4.301   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-43877",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:06:00.730463Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-12T17:33:17.774Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:06:27.712Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/pci/ivtv/ivtv-udma.c",
            "drivers/media/pci/ivtv/ivtv-yuv.c",
            "drivers/media/pci/ivtv/ivtvfb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "38f72c7e7c6b55614f9407555fd5ce9d019b0fa4",
              "status": "affected",
              "version": "4551236b55e80b2c1720b10b77e9400118b2339e",
              "versionType": "git"
            },
            {
              "lessThan": "81d0664bed91a858c7b50c263954b59d65f1b414",
              "status": "affected",
              "version": "66c8a83bf1de2eb3eea4734c7eda22255a965f11",
              "versionType": "git"
            },
            {
              "lessThan": "24062aa7407091dee3e45a8e8037df437e848718",
              "status": "affected",
              "version": "1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1",
              "versionType": "git"
            },
            {
              "lessThan": "3d8fd92939e21ff0d45100ab208f8124af79402a",
              "status": "affected",
              "version": "1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1",
              "versionType": "git"
            },
            {
              "lessThan": "c766065e8272085ea9c436414b7ddf1f12e7787b",
              "status": "affected",
              "version": "1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1",
              "versionType": "git"
            },
            {
              "lessThan": "629913d6d79508b166c66e07e4857e20233d85a9",
              "status": "affected",
              "version": "1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1b00b7335000c0e107f774cc8ee4d5340f824f28",
              "versionType": "git"
            },
            {
              "lessThan": "5.5",
              "status": "affected",
              "version": "5.4.301",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/pci/ivtv/ivtv-udma.c",
            "drivers/media/pci/ivtv/ivtv-yuv.c",
            "drivers/media/pci/ivtv/ivtvfb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "lessThan": "5.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.103",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.44",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.103",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.44",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.3",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.4.301",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: ivtv: Add check for DMA map result\n\nIn case DMA fails, \u0027dma-\u003eSG_length\u0027 is 0. This value is later used to\naccess \u0027dma-\u003eSGarray[dma-\u003eSG_length - 1]\u0027, which will cause out of\nbounds access.\n\nAdd check to return early on invalid value. Adjust warnings accordingly.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is reached only through local device nodes \u2014 `write()`/`ioctl(IVTVFB_IOC_DMA_FRAME)` on `/dev/fbN` and `write()`/`ioctl(IVTV_IOC_DMA_FRAME)` on the ivtv decoder video node. No remote or adjacent-network input reaches this path.\nAC:L - The attacker fully controls the userspace buffer address and the transfer size (up to 704 pages per call) and can retry the operation in an unbounded loop; because the card is 32-bit DMA-masked, every high page consumes shared swiotlb/32-bit IOVA resources that the attacker can pressure and exhaust, and once `dma_map_sg()` returns 0 the out-of-bounds write is deterministic.\nPR:L - There is no `capable()` or other privilege check anywhere along the path \u2014 access is governed solely by permissions on `/dev/video*` and `/dev/fb*`, which are held by ordinary console/desktop users in the `video` group and by non-root media daemons on set-top-box and embedded appliances.\nUI:N - The attacker triggers the bug entirely from their own process with a single `write()` or `ioctl()` call; no action by any other user is required.\nS:U - The corruption and its consequences stay within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed by the negative-index write itself.\nC:H - The corrupted `bouncemap[703]` page pointer is subsequently used as a bounce-buffer source, and the driver additionally programs the card with a stale SG array of already-unmapped DMA addresses, causing kernel memory the driver no longer owns to be copied into decoder RAM that userspace can read back \u2014 a memory-corruption primitive leveragable for arbitrary kernel disclosure.\nI:H - This is an out-of-bounds write that ORs bit 63 into an adjacent `struct page *`, and that poisoned pointer is later fed to `page_address()` + `memcpy()` with attacker-controlled data and to `__free_page()` \u2014 yielding a wild kernel write and page-allocator corruption suitable for control-flow hijacking.\nA:H - The failed transfer leaves no SG entry tagged with the completion-interrupt bit and arms no DMA timeout timer, so the caller loops forever in `schedule()` while holding `itv-\u003eudma.lock`, permanently wedging the driver; the wild `__free_page()`/`page_address()` dereferences additionally produce a kernel oops."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:36:53.441Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/38f72c7e7c6b55614f9407555fd5ce9d019b0fa4"
        },
        {
          "url": "https://git.kernel.org/stable/c/81d0664bed91a858c7b50c263954b59d65f1b414"
        },
        {
          "url": "https://git.kernel.org/stable/c/24062aa7407091dee3e45a8e8037df437e848718"
        },
        {
          "url": "https://git.kernel.org/stable/c/3d8fd92939e21ff0d45100ab208f8124af79402a"
        },
        {
          "url": "https://git.kernel.org/stable/c/c766065e8272085ea9c436414b7ddf1f12e7787b"
        },
        {
          "url": "https://git.kernel.org/stable/c/629913d6d79508b166c66e07e4857e20233d85a9"
        }
      ],
      "title": "media: pci: ivtv: Add check for DMA map result",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-43877",
    "datePublished": "2024-08-21T00:06:29.330Z",
    "dateReserved": "2024-08-17T09:11:59.281Z",
    "dateUpdated": "2026-08-05T11:36:53.441Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:06:27.712Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-43877\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:06:00.730463Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:22.617Z\"}}], \"cna\": {\"title\": \"media: pci: ivtv: Add check for DMA map result\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4551236b55e80b2c1720b10b77e9400118b2339e\", \"lessThan\": \"38f72c7e7c6b55614f9407555fd5ce9d019b0fa4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"66c8a83bf1de2eb3eea4734c7eda22255a965f11\", \"lessThan\": \"81d0664bed91a858c7b50c263954b59d65f1b414\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1\", \"lessThan\": \"24062aa7407091dee3e45a8e8037df437e848718\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1\", \"lessThan\": \"3d8fd92939e21ff0d45100ab208f8124af79402a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1\", \"lessThan\": \"c766065e8272085ea9c436414b7ddf1f12e7787b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1\", \"lessThan\": \"629913d6d79508b166c66e07e4857e20233d85a9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1b00b7335000c0e107f774cc8ee4d5340f824f28\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.4.301\", \"lessThan\": \"5.5\", \"versionType\": \"semver\"}], \"programFiles\": [\"drivers/media/pci/ivtv/ivtv-udma.c\", \"drivers/media/pci/ivtv/ivtv-yuv.c\", \"drivers/media/pci/ivtv/ivtvfb.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.16\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.16\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.103\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.44\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/media/pci/ivtv/ivtv-udma.c\", \"drivers/media/pci/ivtv/ivtv-yuv.c\", \"drivers/media/pci/ivtv/ivtvfb.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/38f72c7e7c6b55614f9407555fd5ce9d019b0fa4\"}, {\"url\": \"https://git.kernel.org/stable/c/81d0664bed91a858c7b50c263954b59d65f1b414\"}, {\"url\": \"https://git.kernel.org/stable/c/24062aa7407091dee3e45a8e8037df437e848718\"}, {\"url\": \"https://git.kernel.org/stable/c/3d8fd92939e21ff0d45100ab208f8124af79402a\"}, {\"url\": \"https://git.kernel.org/stable/c/c766065e8272085ea9c436414b7ddf1f12e7787b\"}, {\"url\": \"https://git.kernel.org/stable/c/629913d6d79508b166c66e07e4857e20233d85a9\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nmedia: pci: ivtv: Add check for DMA map result\\n\\nIn case DMA fails, \u0027dma-\u003eSG_length\u0027 is 0. This value is later used to\\naccess \u0027dma-\u003eSGarray[dma-\u003eSG_length - 1]\u0027, which will cause out of\\nbounds access.\\n\\nAdd check to return early on invalid value. Adjust warnings accordingly.\\n\\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.103\", \"versionStartIncluding\": \"5.16\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.44\", \"versionStartIncluding\": \"5.16\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.3\", \"versionStartIncluding\": \"5.16\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"5.16\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.4.301\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-23T15:53:07.042Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-43877\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-23T15:53:07.042Z\", \"dateReserved\": \"2024-08-17T09:11:59.281Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-08-21T00:06:29.330Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…