In the Linux kernel, the following vulnerability has been resolved:
dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type
In zynqmp_dma_alloc/free_chan_resources functions there is a potential overflow in the below expressions.
dma_alloc_coherent(chan->dev, (2 * chan->desc_size * ZYNQMP_DMA_NUM_DESCS), &chan->desc_pool_p, GFP_KERNEL);
dma_free_coherent(chan->dev,(2 * ZYNQMP_DMA_DESC_SIZE(chan) * ZYNQMP_DMA_NUM_DESCS), chan->desc_pool_v, chan->desc_pool_p);
The arguments desc_size and ZYNQMP_DMA_NUM_DESCS were 32 bit. Though this overflow condition is not observed but it is a potential problem in the case of 32-bit multiplication. Hence fix it by changing the desc_size data type to size_t.
In addition to coverity fix it also reuse ZYNQMP_DMA_DESC_SIZE macro in dma_alloc_coherent API argument.
Addresses-Coverity: Event overflow_before_widen.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotg-5.15Upgrade linux-oracle-5.15Upgrade linux-gcp-fipsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-riscv-5.15Upgrade linux-hwe-5.15Upgrade linux-kvmUpgrade linux-aws-5.4Upgrade linux-oracleUpgrade linux-azure-fde-5.15Upgrade linux-gcp-5.15Upgrade linux-gcpUpgrade linux-ibmUpgrade linux-azureUpgrade linux-fipsUpgrade linux-realtimeUpgrade linux-hwe-5.4Upgrade linux-gkeopUpgrade linux-aws-fipsUpgrade linux-lowlatencyUpgrade linux-nvidiaUpgrade linux-azure-5.15Upgrade linux-azure-5.4Upgrade linux-bluefieldUpgrade linux-intel-iotgUpgrade linux-gkeUpgrade linux-raspiUpgrade linux-azure-fipsUpgrade linux-aws-5.15Upgrade linux-ibm-5.4Upgrade linuxUpgrade linux-oracle-5.4Upgrade linux-raspi-5.4Upgrade linux-awsUpgrade linux-iotUpgrade linux-gcp-5.4 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub