cbcvebase.
CVE-2024-57929
published 2025-01-19

CVE-2024-57929: In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice in dm_array_cursor_end When…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice in dm_array_cursor_end When dm_bm_read_lock() fails due to locking or checksum errors, it releases the faulty block implicitly while leaving an invalid output pointer behind. The caller of dm_bm_read_lock() should not operate on this invalid dm_block pointer, or it will lead to undefined result. For example, the dm_array_cursor incorrectly caches the invalid pointer on reading a faulty array block, causing a double release in dm_array_cursor_end(), then hitting the BUG_ON in dm-bufio cache_put(). Reproduce steps: 1. initialize a cache device dmsetup create cmeta --table "0 8192 linear /dev/sdc 0" dmsetup create cdata --table "0 65536 linear /dev/sdc 8192" dmsetup create corig --table "0 524288 linear /dev/sdc $262144" dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 dmsetup create cache --table "0 524288 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0" 2. wipe the second array block offline dmsteup remove cache cmeta cdata corig mapping_root=$(dd if=/dev/sdc bs=1c count=8 skip=192 \ 2>/dev/null | hexdump -e '1/8 "%u\n"') ablock=$(dd if=/dev/sdc bs=1c count=8 skip=$((4096*mapping_root+2056)) \ 2>/dev/null | hexdump -e '1/8 "%u\n"') dd if=/dev/zero of=/dev/sdc bs=4k count=1 seek=$ablock 3. try reopen the cache device dmsetup create cmeta --table "0 8192 linear /dev/sdc 0" dmsetup create cdata --table "0 65536 linear /dev/sdc 8192" dmsetup create corig --table "0 524288 linear /dev/sdc $262144" dmsetup create cache --table "0 524288 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0" Kernel logs: (snip) device-mapper: array: array_block_check failed: blocknr 0 != wanted 10 device-mapper: block manager: array validator check failed for block 10 device-mapper: array: get_ablock failed device-mapper: cache metadata: dm_array_cursor_next for mapping

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < 9c7c03d0e926762adf3a3a0ba86156fb5e19538b9c7c03d0e926762adf3a3a0ba86156fb5e19538b
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < fc1ef07c3522e257e32702954f265debbcb096a7fc1ef07c3522e257e32702954f265debbcb096a7
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < 738994872d77e189b2d13c501a1d145e95d98f46738994872d77e189b2d13c501a1d145e95d98f46
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < e477021d252c007f0c6d45b5d13d341efed03979e477021d252c007f0c6d45b5d13d341efed03979
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < 6002bec5354f86d1a2df21468f68e3ec03ede9da6002bec5354f86d1a2df21468f68e3ec03ede9da
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < 017c4470bff53585370028fec9341247bad358ff017c4470bff53585370028fec9341247bad358ff
linuxlinux>= fdd1315aa5f022fe6574efdc2d9535f75a0ee255 < f2893c0804d86230ffb8f1c8703fdbb18648abc8f2893c0804d86230ffb8f1c8703fdbb18648abc8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 4.9 < 5.4.2905.4.290
linuxlinux_kernel>= 5.11 < 5.15.1775.15.177
linuxlinux_kernel>= 5.16 < 6.1.1256.1.125
linuxlinux_kernel>= 5.5 < 5.10.2345.10.234
linuxlinux_kernel>= 6.2 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.