Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma-pcie: Reject devices without driver data
dw_edma_pcie_probe() treats the PCI device ID driver_data as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference.
Reject such matches before enabling the device.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 4.19.0 (+2 more)