Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-58006— PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于PCI: dwc: ep模块在pci_epc_set_bar函数中未防止更改BAR大小和标志。

CVSS 9.6 · Critical EPSS 0.23% · P14

Possible ATT&CK Techniques 1 AI

T1041 · Exfiltration Over C2 Channel

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 4284c88fff0efc4e418abb53d78e02dc4f099d6c< b5cacfd067060c75088363ed3e19779078be2755 affected
4284c88fff0efc4e418abb53d78e02dc4f099d6c< 3229c15d6267de8e704b4085df8a82a5af2d63eb affected
4284c88fff0efc4e418abb53d78e02dc4f099d6c< 3708acbd5f169ebafe1faa519cb28adc56295546 affected
6.0 affected
< 6.0 unaffected
6.12.14≤ 6.12.* unaffected
6.13.3≤ 6.13.* unaffected
6.14≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-58006

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar() In commit 4284c88fff0e ("PCI: designware-ep: Allow pci_epc_set_bar() update inbound map address") set_bar() was modified to support dynamically changing the backing physical address of a BAR that was already configured. This means that set_bar() can be called twice, without ever calling clear_bar() (as calling clear_bar() would clear the BAR's PCI address assigned by the host). This can only be done if the new BAR size/flags does not differ from the existing BAR configuration. Add these missing checks. If we allow set_bar() to set e.g. a new BAR size that differs from the existing BAR size, the new address translation range will be smaller than the BAR size already determined by the host, which would mean that a read past the new BAR size would pass the iATU untranslated, which could allow the host to read memory not belonging to the new struct pci_epf_bar. While at it, add comments which clarifies the support for dynamically changing the physical address of a BAR. (Which was also missing.)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于PCI: dwc: ep模块在pci_epc_set_bar函数中未防止更改BAR大小和标志。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 4284c88fff0efc4e418abb53d78e02dc4f099d6c ~ b5cacfd067060c75088363ed3e19779078be2755 -
Linux Linux 6.0 -

II. Public POCs for CVE-2024-58006

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-58006

登录查看更多情报信息。

Patches & Fixes for CVE-2024-58006 (3)

Same Patch Batch · Linux · 2025-02-27 · 177 CVEs total

CVE-2025-21707 9.8 CRITICAL mptcp: consolidate suboption status
CVE-2025-21805 9.8 CRITICAL RDMA/rtrs: Add missing deinit() call
CVE-2025-21748 9.8 CRITICAL ksmbd: fix integer overflows on 32 bit systems
CVE-2025-21796 9.8 CRITICAL nfsd: clear acl_access/acl_default after releasing them
CVE-2024-57997 8.8 HIGH wifi: wcn36xx: fix channel survey memory allocation size
CVE-2024-57995 8.8 HIGH wifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev()
CVE-2024-57999 8.8 HIGH powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
CVE-2025-21735 8.8 HIGH NFC: nci: Add bounds checking in nci_hci_create_pipe()
CVE-2025-21710 8.2 HIGH tcp: correct handling of extreme memory squeeze
CVE-2025-21762 8.1 HIGH arp: use RCU protection in arp_xmit()
CVE-2025-21765 8.1 HIGH ipv6: use RCU protection in ip6_default_advmss()
CVE-2025-21766 8.1 HIGH ipv4: use RCU protection in __ip_rt_update_pmtu()
CVE-2024-57973 8.1 HIGH rdma/cxgb4: Prevent potential integer overflow on 32bit
CVE-2025-21760 8.1 HIGH ndisc: extend RCU protection in ndisc_send_skb()
CVE-2025-21717 7.8 HIGH net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq
CVE-2025-21738 7.8 HIGH ata: libata-sff: Ensure that we cannot write outside the allocated buffer
CVE-2025-21729 7.8 HIGH wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion
CVE-2025-21727 7.8 HIGH padata: fix UAF in padata_reorder
CVE-2025-21753 7.8 HIGH btrfs: fix use-after-free when attempting to join an aborted transaction
CVE-2025-21785 7.8 HIGH arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array

Showing top 20 of 177 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-58006

No comments yet


Leave a comment