CVE-2024-46716: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor Remove list_del call in msgdma_chan_desc_cleanup, this should be the role of msgdma_free_descriptor. In consequence replace list_add_tail with list_move_tail in msgdma_free_descriptor. This fixes the path: msgdma_free_chan_resources -> msgdma_free_descriptors -> msgdma_free_desc_list -> msgdma_free_descriptor which does not correctly free the descriptors as first nodes were not removed from the list.

Affected products

  • Linux Linux Kernel: before 6.1.109 (fixed in 6.1.109); from 6.2, before 6.6.50 (fixed in 6.6.50); from 6.7, before 6.10.9 (fixed in 6.10.9)

Published 2024-09-18. Last modified 2026-08-04.