cbcvebase.
CVE-2024-35797
published 2024-05-17

CVE-2024-35797: In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.65%
47.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that could result in a false "recently evicted" count. Such a false positive wouldn't be the end of the world. But for code clarity and (future) robustness, be explicit about this case. Bail on get_shadow_from_swap_cache() returning NULL.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= cf264e1329fb0307e044f7675849f9f38b44c11a < b79f9e1ff27c994a4c452235ba09e672ec698e23b79f9e1ff27c994a4c452235ba09e672ec698e23
linuxlinux>= cf264e1329fb0307e044f7675849f9f38b44c11a < d962f6c583458037dc7e529659b2b02b9dd3d94bd962f6c583458037dc7e529659b2b02b9dd3d94b
linuxlinux>= cf264e1329fb0307e044f7675849f9f38b44c11a < 24a0e73d544439bb9329fbbafac44299e548a67724a0e73d544439bb9329fbbafac44299e548a677
linuxlinux>= cf264e1329fb0307e044f7675849f9f38b44c11a < d5d39c707a4cf0bcc84680178677b97aa2cb2627d5d39c707a4cf0bcc84680178677b97aa2cb2627
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.5 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.