cbcvebase.
CVE-2024-53113
published 2024-12-02

CVE-2024-53113: In the Linux kernel, the following vulnerability has been resolved: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof We triggered a NULL pointer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof We triggered a NULL pointer dereference for ac.preferred_zoneref->zone in alloc_pages_bulk_noprof() when the task is migrated between cpusets. When cpuset is enabled, in prepare_alloc_pages(), ac->nodemask may be ¤t->mems_allowed. when first_zones_zonelist() is called to find preferred_zoneref, the ac->nodemask may be modified concurrently if the task is migrated between different cpusets. Assuming we have 2 NUMA Node, when traversing Node1 in ac->zonelist, the nodemask is 2, and when traversing Node2 in ac->zonelist, the nodemask is 1. As a result, the ac->preferred_zoneref points to NULL zone. In alloc_pages_bulk_noprof(), for_each_zone_zonelist_nodemask() finds a allowable zone and calls zonelist_node_idx(ac.preferred_zoneref), leading to NULL pointer dereference. __alloc_pages_noprof() fixes this issue by checking NULL pointer in commit ea57485af8f4 ("mm, page_alloc: fix check for NULL preferred_zone") and commit df76cee6bbeb ("mm, page_alloc: remove redundant checks from alloc fastpath"). To fix it, check NULL pointer for preferred_zoneref->zone.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 387ba26fb1cb9be9e35dc14a6d97188e916eda05 < 903d896448c2e50e8652aaba529a30d4d1eaa0e5903d896448c2e50e8652aaba529a30d4d1eaa0e5
linuxlinux>= 387ba26fb1cb9be9e35dc14a6d97188e916eda05 < 6addb2d9501ec866d7b3a3b4e665307c437e9be26addb2d9501ec866d7b3a3b4e665307c437e9be2
linuxlinux>= 387ba26fb1cb9be9e35dc14a6d97188e916eda05 < d0f16cec79774c3132df006cf771eddd89d08f58d0f16cec79774c3132df006cf771eddd89d08f58
linuxlinux>= 387ba26fb1cb9be9e35dc14a6d97188e916eda05 < 31502374627ba9ec3e710dbd0bb00457cc6d2c1931502374627ba9ec3e710dbd0bb00457cc6d2c19
linuxlinux>= 387ba26fb1cb9be9e35dc14a6d97188e916eda05 < 8ce41b0f9d77cca074df25afd39b86e2ee3aa68e8ce41b0f9d77cca074df25afd39b86e2ee3aa68e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.13 < 6.1.1196.1.119
linuxlinux_kernel>= 6.2 < 6.6.636.6.63
linuxlinux_kernel>= 6.7 < 6.11.106.11.10
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.