cbcvebase.
CVE-2024-26960
published 2024-05-01

CVE-2024-26960: In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix race between free_swap_and_cache() and swapoff() There was previously a…

PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix race between free_swap_and_cache() and swapoff() There was previously a theoretical window where swapoff() could run and teardown a swap_info_struct while a call to free_swap_and_cache() was running in another thread. This could cause, amongst other bad possibilities, swap_page_trans_huge_swapped() (called by free_swap_and_cache()) to access the freed memory for swap_map. This is a theoretical problem and I haven't been able to provoke it from a test case. But there has been agreement based on code review that this is possible (see link below). Fix it by using get_swap_device()/put_swap_device(), which will stall swapoff(). There was an extra check in _swap_info_get() to confirm that the swap entry was not free. This isn't present in get_swap_device() because it doesn't make sense in general due to the race between getting the reference and swapoff. So I've added an equivalent check directly in free_swap_and_cache(). Details of how to provoke one possible issue (thanks to David Hildenbrand for deriving this): --8try_to_unuse() will stop as soon as soon as si->inuse_pages==0. So the question is: could someone reclaim the folio and turn si->inuse_pages==0, before we completed swap_page_trans_huge_swapped(). Imagine the following: 2 MiB folio in the swapcache. Only 2 subpages are still references by swap entries. Process 1 still references subpage 0 via swap entry. Process 2 still references subpage 1 via swap entry. Process 1 quits. Calls free_swap_and_cache(). -> count == SWAP_HAS_CACHE [then, preempted in the hypervisor etc.] Process 2 quits. Calls free_swap_and_cache(). -> count == SWAP_HAS_CACHE Process 2 goes ahead, passes swap_page_trans_huge_swapped(), and calls __try_to_reclaim_swap(). __try_to_reclaim_swap()->folio_free_swap()->delete_from_swap_cache()-> put_swap_folio()->free_swap_slot()->swapcache_free_entries()-> swap_entry_free()->swap_range_free()-> ... WRITE_O

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < d85c11c97ecf92d47a4b29e3faca714dc1f18d0dd85c11c97ecf92d47a4b29e3faca714dc1f18d0d
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 2da5568ee222ce0541bfe446a07998f92ed1643e2da5568ee222ce0541bfe446a07998f92ed1643e
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 1ede7f1d7eed1738d1b9333fd1e152ccb450b86a1ede7f1d7eed1738d1b9333fd1e152ccb450b86a
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 0f98f6d2fb5fad00f8299b84b85b6bc1b6d7d19a0f98f6d2fb5fad00f8299b84b85b6bc1b6d7d19a
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 3ce4c4c653e4e478ecb15d3c88e690f12cbf6b393ce4c4c653e4e478ecb15d3c88e690f12cbf6b39
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 363d17e7f7907c8e27a9e86968af0eaa2301787b363d17e7f7907c8e27a9e86968af0eaa2301787b
linuxlinux>= 7c00bafee87c7bac7ed9eced7c161f8e5332cb4e < 82b1c07a0af603e3c47b906c8e991dc96f01688e82b1c07a0af603e3c47b906c8e991dc96f01688e
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-198.2185.4.0-198.218
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 4.11 < 5.10.2155.10.215
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.