cbcvebase.
CVE-2024-41021
published 2024-07-29

CVE-2024-41021: In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC on s390. Therefore we do not expect to see VM_FAULT_HWPOISON in do_exception(). However, since commit af19487f00f3 ("mm: make PTE_MARKER_SWAPIN_ERROR more general"), it is possible to see VM_FAULT_HWPOISON in combination with PTE_MARKER_POISONED, even on architectures that do not support HWPOISON otherwise. In this case, we will end up on the BUG() in do_exception(). Fix this by treating VM_FAULT_HWPOISON the same as VM_FAULT_SIGBUS, similar to x86 when MEMORY_FAILURE is not configured. Also print unexpected fault flags, for easier debugging. Note that VM_FAULT_HWPOISON_LARGE is not expected, because s390 cannot support swap entries on other levels than PTE level.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.12-1 (forky)linux 6.9.12-1 (forky)
linuxlinux
linuxlinux>= af19487f00f34ff8643921d7909dbb3fedc7e329 < 73a9260b7366d2906ec011e100319359fe2277d073a9260b7366d2906ec011e100319359fe2277d0
linuxlinux>= af19487f00f34ff8643921d7909dbb3fedc7e329 < 9e13767ccefdc4f8aa92514b592b60f6b54882ff9e13767ccefdc4f8aa92514b592b60f6b54882ff
linuxlinux>= af19487f00f34ff8643921d7909dbb3fedc7e329 < a3aefb871222a9880602d1a44a558177b4143e3ba3aefb871222a9880602d1a44a558177b4143e3b
linuxlinux>= af19487f00f34ff8643921d7909dbb3fedc7e329 < df39038cd89525d465c2c8827eb64116873f141adf39038cd89525d465c2c8827eb64116873f141a
linuxlinux_kernel>= 0 < 6.9.12-16.9.12-1
linuxlinux_kernel>= 0 < 6.9.12-16.9.12-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 6.10 < 6.10.26.10.2
linuxlinux_kernel>= 6.6 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.9.126.9.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.