cbcvebase.
CVE-2024-50066
published 2024-10-23

CVE-2024-50066: In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables()…

PriorityP434high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables() looks at the type of the PMD entry and the specified address range to figure out by which method the next chunk of page table entries should be moved. At that point, the mmap_lock is held in write mode, but no rmap locks are held yet. For PMD entries that point to page tables and are fully covered by the source address range, move_pgt_entry(NORMAL_PMD, ...) is called, which first takes rmap locks, then does move_normal_pmd(). move_normal_pmd() takes the necessary page table locks at source and destination, then moves an entire page table from the source to the destination. The problem is: The rmap locks, which protect against concurrent page table removal by retract_page_tables() in the THP code, are only taken after the PMD entry has been read and it has been decided how to move it. So we can race as follows (with two processes that have mappings of the same tmpfs file that is stored on a tmpfs mount with huge=advise); note that process A accesses page tables through the MM while process B does it through the file rmap: process A process B ========= ========= mremap mremap_to move_vma move_page_tables get_old_pmd alloc_new_pmd *** PREEMPT *** madvise(MADV_COLLAPSE) do_madvise madvise_walk_vmas madvise_vma_behavior madvise_collapse hpage_collapse_scan_file collapse_file retract_page_tables i_mmap_lock_read(mapping) pmdp_collapse_flush i_mmap_unlock_read(mapping) move_pgt_entry(NORMAL_PMD, ...) take_rmap_locks move_normal_pmd drop_rmap_locks When this happens, move_normal_pmd() can end up creating bogus PMD entries in the line `pmd_populate(mm, new_pmd, pmd_pgtable(pmd))`. The effect depends on arch-specific and machine-specific details; on x86, you can end up with physical page 0 mapped as a page table, which is likely exploitable for user->kernel privilege escalation. Fix the race by letting process B rec

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.5-1 (forky)linux 6.11.5-1 (forky)
googlechrome_chrome
linuxlinux
linuxlinux>= 1d65b771bc08cd054cf6d3766a72e113dc46d62f < 17396e32f975130b3e6251f024c8807d192e4c3e17396e32f975130b3e6251f024c8807d192e4c3e
linuxlinux>= 1d65b771bc08cd054cf6d3766a72e113dc46d62f < 1552ce9ce8af47c0fe911682e5e1855e25851ca91552ce9ce8af47c0fe911682e5e1855e25851ca9
linuxlinux>= 1d65b771bc08cd054cf6d3766a72e113dc46d62f < 6fa1066fc5d00cb9f1b0e83b7ff6ef98d26ba2aa6fa1066fc5d00cb9f1b0e83b7ff6ef98d26ba2aa
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.6 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.0LOW
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.