CVE-2024-44949
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-44949 affects the Linux kernel's parisc architecture implementation. The vulnerability was discovered due to an incorrect DMA alignment configuration where ARCH_DMA_MINALIGN was defined as 16 bytes, which is too small. This vulnerability was disclosed on September 4, 2024, and affects Linux kernel versions up to 6.6.46 and versions from 6.7 up to 6.10.5 (NVD).

Technical details

The vulnerability stems from the possibility of two unrelated 16-byte allocations sharing a cache line. When one allocation is written using DMA and the other using cached write, the value written with DMA may become corrupted. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability can lead to DMA corruption in affected systems using the parisc architecture. When exploited, it could result in data corruption when DMA operations are performed, potentially affecting system stability and data integrity (Kernel Patch).

Mitigation and workarounds

The vulnerability has been fixed by changing ARCH_DMA_MINALIGN to 128 on PA20 and 32 on PA1.1, which represents the largest possible cache line size. Additionally, the fix introduces dynamic tuning of slab cache parameters based on detected cache line size through the implementation of arch_slab_minalign(), cache_line_size(), and dma_get_cache_alignment() functions (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management