CVE-2024-42251
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2024
Last modified:
06/09/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mm: page_ref: remove folio_try_get_rcu()<br />
<br />
The below bug was reported on a non-SMP kernel:<br />
<br />
[ 275.267158][ T4335] ------------[ cut here ]------------<br />
[ 275.267949][ T4335] kernel BUG at include/linux/page_ref.h:275!<br />
[ 275.268526][ T4335] invalid opcode: 0000 [#1] KASAN PTI<br />
[ 275.269001][ T4335] CPU: 0 PID: 4335 Comm: trinity-c3 Not tainted 6.7.0-rc4-00061-gefa7df3e3bb5 #1<br />
[ 275.269787][ T4335] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014<br />
[ 275.270679][ T4335] RIP: 0010:try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.272813][ T4335] RSP: 0018:ffffc90005dcf650 EFLAGS: 00010202<br />
[ 275.273346][ T4335] RAX: 0000000000000246 RBX: ffffea00066e0000 RCX: 0000000000000000<br />
[ 275.274032][ T4335] RDX: fffff94000cdc007 RSI: 0000000000000004 RDI: ffffea00066e0034<br />
[ 275.274719][ T4335] RBP: ffffea00066e0000 R08: 0000000000000000 R09: fffff94000cdc006<br />
[ 275.275404][ T4335] R10: ffffea00066e0037 R11: 0000000000000000 R12: 0000000000000136<br />
[ 275.276106][ T4335] R13: ffffea00066e0034 R14: dffffc0000000000 R15: ffffea00066e0008<br />
[ 275.276790][ T4335] FS: 00007fa2f9b61740(0000) GS:ffffffff89d0d000(0000) knlGS:0000000000000000<br />
[ 275.277570][ T4335] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
[ 275.278143][ T4335] CR2: 00007fa2f6c00000 CR3: 0000000134b04000 CR4: 00000000000406f0<br />
[ 275.278833][ T4335] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000<br />
[ 275.279521][ T4335] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400<br />
[ 275.280201][ T4335] Call Trace:<br />
[ 275.280499][ T4335] <br />
[ 275.280751][ T4335] ? die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434 arch/x86/kernel/dumpstack.c:447)<br />
[ 275.281087][ T4335] ? do_trap (arch/x86/kernel/traps.c:112 arch/x86/kernel/traps.c:153)<br />
[ 275.281463][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.281884][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.282300][ T4335] ? do_error_trap (arch/x86/kernel/traps.c:174)<br />
[ 275.282711][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.283129][ T4335] ? handle_invalid_op (arch/x86/kernel/traps.c:212)<br />
[ 275.283561][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.283990][ T4335] ? exc_invalid_op (arch/x86/kernel/traps.c:264)<br />
[ 275.284415][ T4335] ? asm_exc_invalid_op (arch/x86/include/asm/idtentry.h:568)<br />
[ 275.284859][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))<br />
[ 275.285278][ T4335] try_grab_folio (mm/gup.c:148)<br />
[ 275.285684][ T4335] __get_user_pages (mm/gup.c:1297 (discriminator 1))<br />
[ 275.286111][ T4335] ? __pfx___get_user_pages (mm/gup.c:1188)<br />
[ 275.286579][ T4335] ? __pfx_validate_chain (kernel/locking/lockdep.c:3825)<br />
[ 275.287034][ T4335] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 1))<br />
[ 275.287416][ T4335] __gup_longterm_locked (mm/gup.c:1509 mm/gup.c:2209)<br />
[ 275.288192][ T4335] ? __pfx___gup_longterm_locked (mm/gup.c:2204)<br />
[ 275.288697][ T4335] ? __pfx_lock_acquire (kernel/locking/lockdep.c:5722)<br />
[ 275.289135][ T4335] ? __pfx___might_resched (kernel/sched/core.c:10106)<br />
[ 275.289595][ T4335] pin_user_pages_remote (mm/gup.c:3350)<br />
[ 275.290041][ T4335] ? __pfx_pin_user_pages_remote (mm/gup.c:3350)<br />
[ 275.290545][ T4335] ? find_held_lock (kernel/locking/lockdep.c:5244 (discriminator 1))<br />
[ 275.290961][ T4335] ? mm_access (kernel/fork.c:1573)<br />
[ 275.291353][ T4335] process_vm_rw_single_vec+0x142/0x360<br />
[ 275.291900][ T4335] ? __pfx_process_vm_rw_single_vec+0x10/0x10<br />
[ 275.292471][ T4335] ? mm_access (kernel/fork.c:1573)<br />
[ 275.292859][ T4335] process_vm_rw_core+0x272/0x4e0<br />
[ 275.293384][ T4335] ? hlock_class (a<br />
---truncated---
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.42 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.9.11 (excluding) |
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc5:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc6:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.10:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page