CVE-2024-40917: memblock: make memblock_set_node() also warn about use of MAX_NUMNODES
In the Linux kernel, the following vulnerability has been resolved:
memblock: make memblocksetnode() also warn about use of MAXNUMNODES
On an (old) x86 system with SRAT just covering space above 4Gb:
ACPI: SRAT: Node 0 PXM 0 [mem 0x100000000-0xfffffffff] hotplug
the commit referenced below leads to this NUMA configuration no longer being refused by a CONFIGNUMA=y kernel (previously
NUMA: nodes only cover 6144MB of your 8185MB e820 RAM. Not used. No NUMA configuration found Faking a node at [mem 0x0000000000000000-0x000000027fffffff]
was seen in the log directly after the message quoted above), because of memblockvalidatenumacoverage() checking for NUMANONODE (only). This in turn led to memblockallocrangenid()'s warning about MAXNUMNODES triggering, followed by a NULL deref in memmapinit() when trying to access node 64's (NODESHIFT=6) node data.
To compensate said change, make memblocksetnode() warn on and adjust a passed in value of MAXNUMNODES, just like various other functions already do.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40917?
CVE-2024-40917 is classified with a severity rating that requires attention due to its potential impact on system stability.
How do I fix CVE-2024-40917?
To fix CVE-2024-40917, upgrade to the latest versions of the Linux kernel specified in the advisory such as 5.10.223-1 or 6.12.13-1.
Which versions of the Linux package are affected by CVE-2024-40917?
CVE-2024-40917 affects multiple versions of the Linux package, including versions older than 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, and 6.12.13-1.
Is CVE-2024-40917 a local or remote vulnerability?
CVE-2024-40917 is primarily considered a local vulnerability, requiring access to the system to exploit.
Who is the vendor for CVE-2024-40917?
The vendor for CVE-2024-40917 is Debian, which maintains the affected Linux kernel packages.