cbcvebase.
CVE-2024-50199
published 2024-11-08

CVE-2024-50199: In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: skip HugeTLB pages for unuse_vma I got a bad pud error and lost a 1GB HugeTLB…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: skip HugeTLB pages for unuse_vma I got a bad pud error and lost a 1GB HugeTLB when calling swapoff. The problem can be reproduced by the following steps: 1. Allocate an anonymous 1GB HugeTLB and some other anonymous memory. 2. Swapout the above anonymous memory. 3. run swapoff and we will get a bad pud error in kernel message: mm/pgtable-generic.c:42: bad pud 00000000743d215d(84000001400000e7) We can tell that pud_clear_bad is called by pud_none_or_clear_bad in unuse_pud_range() by ftrace. And therefore the HugeTLB pages will never be freed because we lost it from page table. We can skip HugeTLB pages for unuse_vma to fix it.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < ba7f982cdb37ff5a7739dec85d7325ea66fc1496ba7f982cdb37ff5a7739dec85d7325ea66fc1496
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < 417d5838ca73c6331ae2fe692fab6c25c00d9a0b417d5838ca73c6331ae2fe692fab6c25c00d9a0b
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < e41710f5a61aca9d6baaa8f53908a927dd9e7aa7e41710f5a61aca9d6baaa8f53908a927dd9e7aa7
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < 6ec0fe3756f941f42f8c57156b8bdf2877b2ebaf6ec0fe3756f941f42f8c57156b8bdf2877b2ebaf
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < bed2b9037806c62166a0ef9a559a1e7e3e1275b8bed2b9037806c62166a0ef9a559a1e7e3e1275b8
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < eb66a833cdd2f7302ee05d05e0fa12a2ca32eb87eb66a833cdd2f7302ee05d05e0fa12a2ca32eb87
linuxlinux>= 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f < 7528c4fb1237512ee18049f852f014eba80bbe8d7528c4fb1237512ee18049f852f014eba80bbe8d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 2.6.36 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1695.15.169
linuxlinux_kernel>= 5.16 < 6.1.1146.1.114
linuxlinux_kernel>= 5.5 < 5.10.2285.10.228
linuxlinux_kernel>= 6.2 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.