cbcvebase.
CVE-2024-45025
published 2024-09-11

CVE-2024-45025: In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the first count/BITS_PER_LONG bits from old->full_fds_bits[] and fill the rest with zeroes. What it does is copying enough words (BITS_TO_LONGS(count/BITS_PER_LONG)), then memsets the rest. That works fine, *if* all bits past the cutoff point are clear. Otherwise we are risking garbage from the last word we'd copied. For most of the callers that is true - expand_fdtable() has count equal to old->max_fds, so there's no open descriptors past count, let alone fully occupied words in ->open_fds[], which is what bits in ->full_fds_bits[] correspond to. The other caller (dup_fd()) passes sane_fdtable_size(old_fdt, max_fds), which is the smallest multiple of BITS_PER_LONG that covers all opened descriptors below max_fds. In the common case (copying on fork()) max_fds is ~0U, so all opened descriptors will be below it and we are fine, by the same reasons why the call in expand_fdtable() is safe. Unfortunately, there is a case where max_fds is less than that and where we might, indeed, end up with junk in ->full_fds_bits[] - close_range(from, to, CLOSE_RANGE_UNSHARE) with * descriptor table being currently shared * 'to' being above the current capacity of descriptor table * 'from' being just under some chunk of opened descriptors. In that case we end up with observably wrong behaviour - e.g. spawn a child with CLONE_FILES, get all descriptors in range 0..127 open, then close_range(64, ~0U, CLOSE_RANGE_UNSHARE) and watch dup(0) ending up with descriptor #128, despite #64 being observably not open. The minimally invasive fix would be to deal with that in dup_fd(). If this proves to add measurable overhead, we can go that way, but let's try to fix copy_fd_bitmaps() first. * new helper: bitmap_copy_and_expand(to, from, bits_to_copy, size). * make copy_fd_bitmaps() take the bitmap size in wo

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < fe5bf14881701119aeeda7cf685f3c226c7380dffe5bf14881701119aeeda7cf685f3c226c7380df
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < 5053581fe5dfb09b58c65dd8462bf5dea71f41ff5053581fe5dfb09b58c65dd8462bf5dea71f41ff
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < 8cad3b2b3ab81ca55f37405ffd1315bcc29480588cad3b2b3ab81ca55f37405ffd1315bcc2948058
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < dd72ae8b0fce9c0bbe9582b9b50820f0407f8d8add72ae8b0fce9c0bbe9582b9b50820f0407f8d8a
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < c69d18f0ac7060de724511537810f10f29a27958c69d18f0ac7060de724511537810f10f29a27958
linuxlinux>= 278a5fbaed89dacd04e9d052f4594ffd0e0585de < 9a2fa1472083580b6c66bdaf291f591e1170123a9a2fa1472083580b6c66bdaf291f591e1170123a
linuxlinux_kernel< 4.19.3214.19.321
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.486.6.48
linuxlinux_kernel>= 6.7 < 6.10.76.10.7
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.