CVE-2024-35880

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/05/2024
Last modified:
24/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> io_uring/kbuf: hold io_buffer_list reference over mmap<br /> <br /> If we look up the kbuf, ensure that it doesn&amp;#39;t get unregistered until<br /> after we&amp;#39;re done with it. Since we&amp;#39;re inside mmap, we cannot safely use<br /> the io_uring lock. Rely on the fact that we can lookup the buffer list<br /> under RCU now and grab a reference to it, preventing it from being<br /> unregistered until we&amp;#39;re done with it. The lookup returns the<br /> io_buffer_list directly with it referenced.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.5 (including) 6.6.26 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7.1 (including) 6.8.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.7:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*