CVE-2024-26832

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2024
Last modified:
02/04/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> mm: zswap: fix missing folio cleanup in writeback race path<br /> <br /> In zswap_writeback_entry(), after we get a folio from<br /> __read_swap_cache_async(), we grab the tree lock again to check that the<br /> swap entry was not invalidated and recycled. If it was, we delete the<br /> folio we just added to the swap cache and exit.<br /> <br /> However, __read_swap_cache_async() returns the folio locked when it is<br /> newly allocated, which is always true for this path, and the folio is<br /> ref&amp;#39;d. Make sure to unlock and put the folio before returning.<br /> <br /> This was discovered by code inspection, probably because this path handles<br /> a race condition that should not happen often, and the bug would not crash<br /> the system, it will only strand the folio indefinitely.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.30 (including) 6.1.80 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.4 (including) 6.6.19 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.7 (excluding)
cpe:2.3:o:linux:linux_kernel:6.3.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*