CVE-2024-39497Reachable Assertion in Linux

Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.0%
top 99.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateApr 24

Description

In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) Lack of check for copy-on-write (COW) mapping in drm_gem_shmem_mmap allows users to call mmap with PROT_WRITE and MAP_PRIVATE flag causing a kernel panic due to BUG_ON in vmf_insert_pfn_prot: BUG_ON((vma->vm_flags & VM_PFNMAP) && is_cow_mapping(vma->vm_flags)); Return -EINVAL early if COW mapping is detected. This bug affects all drm drivers using default shmem

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel5.25.10.229+5
Debianlinux/linux_kernel< 5.10.234-1+3
Ubuntulinux/linux_kernel< 5.15.0-133.144+1
CVEListV5linux/linux2194a63a818db71065ebe09c8104f5f021ca4e7ba508a102edf8735adc9bb73d37dd13c38d1a1b10+6
debiandebian/linux< linux 6.1.115-1 (bookworm)

Patches

🔴Vulnerability Details

23
OSV
linux-ibm-5.15 vulnerabilities2025-04-24
OSV
linux-nvidia-tegra, linux-nvidia-tegra-igx vulnerabilities2025-03-28
OSV
linux-xilinx-zynqmp vulnerabilities2025-03-28
OSV
linux-aws-5.15, linux-kvm vulnerabilities2025-03-27
OSV
linux-hwe-5.15 vulnerabilities2025-03-05

📋Vendor Advisories

23
Ubuntu
Linux kernel (IBM) vulnerabilities2025-04-24
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-03-28
Ubuntu
Linux kernel (NVIDIA Tegra) vulnerabilities2025-03-28
Ubuntu
Linux kernel vulnerabilities2025-03-27
Ubuntu
Linux kernel vulnerabilities2025-03-05