CVE-2024-41033

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/07/2024
Last modified:
24/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> cachestat: do not flush stats in recency check<br /> <br /> syzbot detects that cachestat() is flushing stats, which can sleep, in its<br /> RCU read section (see [1]). This is done in the workingset_test_recent()<br /> step (which checks if the folio&amp;#39;s eviction is recent).<br /> <br /> Move the stat flushing step to before the RCU read section of cachestat,<br /> and skip stat flushing during the recency check.<br /> <br /> [1]: https://lore.kernel.org/cgroups/000000000000f71227061bdf97e0@google.com/

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.9.10 (excluding)
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc7:*:*:*:*:*:*