cbcvebase.
CVE-2024-35831
published 2024-05-17

CVE-2024-35831: In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix release of pinned pages when __io_uaddr_map fails Looking at the error path…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix release of pinned pages when __io_uaddr_map fails Looking at the error path of __io_uaddr_map, if we fail after pinning the pages for any reasons, ret will be set to -EINVAL and the error handler won't properly release the pinned pages. I didn't manage to trigger it without forcing a failure, but it can happen in real life when memory is heavily fragmented.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 223ef474316466e9f61f6e0064f3a6fe4923a2c5 < 0b6f39c175ba5f0ef72bdb3b9d2a06ad78621d620b6f39c175ba5f0ef72bdb3b9d2a06ad78621d62
linuxlinux>= 223ef474316466e9f61f6e0064f3a6fe4923a2c5 < 712e2c8415f55a4a4ddaa98a430b87f624109f69712e2c8415f55a4a4ddaa98a430b87f624109f69
linuxlinux>= 223ef474316466e9f61f6e0064f3a6fe4923a2c5 < 4d376d7ad62b6a8e8dfff56b559d9d275e5b9b3a4d376d7ad62b6a8e8dfff56b559d9d275e5b9b3a
linuxlinux>= 223ef474316466e9f61f6e0064f3a6fe4923a2c5 < 67d1189d1095d471ed7fa426c7e384a7140a5dd767d1189d1095d471ed7fa426c7e384a7140a5dd7
linuxlinux>= 6.5.7 < 6.66.6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.5.7 < 6.66.6
linuxlinux_kernel>= 6.6.1 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.