CVE-2024-38384
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
24/06/2024
Last modified:
24/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
blk-cgroup: fix list corruption from reorder of WRITE ->lqueued<br />
<br />
__blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start<br />
is being executed.<br />
<br />
If WRITE of `->lqueued` is re-ordered with READ of &#39;bisc->lnode.next&#39; in<br />
the loop of __blkcg_rstat_flush(), `next_bisc` can be assigned with one<br />
stat instance being added in blk_cgroup_bio_start(), then the local<br />
list in __blkcg_rstat_flush() could be corrupted.<br />
<br />
Fix the issue by adding one barrier.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.9.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/714e59b5456e4d6e4295a9968c564abe193f461c
- https://git.kernel.org/stable/c/785298ab6b802afa75089239266b6bbea590809c
- https://git.kernel.org/stable/c/d0aac2363549e12cc79b8e285f13d5a9f42fd08e
- https://git.kernel.org/stable/c/714e59b5456e4d6e4295a9968c564abe193f461c
- https://git.kernel.org/stable/c/785298ab6b802afa75089239266b6bbea590809c
- https://git.kernel.org/stable/c/d0aac2363549e12cc79b8e285f13d5a9f42fd08e



