Back

HIGH

dmaengine: idxd: Prevent use after free on completion memory

Published Aug 21, 2024

Description

On driver unload any pending descriptors are flushed at the time the interrupt is freed: idxd_dmaengine_drv_remove() -> drv_disable_wq() -> idxd_wq_free_irq() -> idxd_flush_pending_descs().

If there are any descriptors present that need to be flushed this flow triggers a "not present" page fault as below:

BUG: unable to handle page fault for address: ff391c97c70c9040 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page

The address that triggers the fault is the address of the descriptor that was freed moments earlier via: drv_disable_wq()->idxd_wq_free_resources()

Fix the use after free by freeing the descriptors after any possible usage. This is done after idxd_wq_reset() to ensure that the memory remains accessible during possible completion writes by the device.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux is not affected because the kernel config param CONFIG_INTEL_IDXD is disabled.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 21, 2024
Updated May 11, 2026
Reserved Jul 16, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 21, 2024