cbcvebase.
CVE-2024-27406
published 2024-05-17

CVE-2024-27406: In the Linux kernel, the following vulnerability has been resolved: lib/Kconfig.debug: TEST_IOV_ITER depends on MMU Trying to run the iov_iter unit test on a…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:

lib/Kconfig.debug: TEST_IOV_ITER depends on MMU

Trying to run the iov_iter unit test on a nommu system such as the qemu
kc705-nommu emulation results in a crash.

KTAP version 1
# Subtest: iov_iter
# module: kunit_iov_iter
1..9
BUG: failure at mm/nommu.c:318/vmap()!
Kernel panic - not syncing: BUG!

The test calls vmap() directly, but vmap() is not supported on nommu
systems, causing the crash. TEST_IOV_ITER therefore needs to depend on
MMU.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.7-1 (forky)linux 6.7.7-1 (forky)
linuxlinux
linuxlinux>= 2d71340ff1d41a5b9fc1b30ded12d638b2e2ae96 < e6316749d603fe9c4c91f6ec3694e06e4de632a3e6316749d603fe9c4c91f6ec3694e06e4de632a3
linuxlinux>= 2d71340ff1d41a5b9fc1b30ded12d638b2e2ae96 < 9e6e541b97762d5b1143070067f7c68f39a408f89e6e541b97762d5b1143070067f7c68f39a408f8
linuxlinux>= 2d71340ff1d41a5b9fc1b30ded12d638b2e2ae96 < 1eb1e984379e2da04361763f66eec90dd75cf63e1eb1e984379e2da04361763f66eec90dd75cf63e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 6.6 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.