CVE-2024-41021: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception()

Published Jul 29, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

s390/mm: Fix VMFAULTHWPOISON handling in doexception()

There is no support for HWPOISON, MEMORYFAILURE, or ARCHHASCOPYMC on s390. Therefore we do not expect to see VMFAULTHWPOISON in doexception().

However, since commit af19487f00f3 ("mm: make PTEMARKERSWAPINERROR more general"), it is possible to see VMFAULTHWPOISON in combination with PTEMARKERPOISONED, even on architectures that do not support HWPOISON otherwise. In this case, we will end up on the BUG() in doexception().

Fix this by treating VMFAULTHWPOISON the same as VMFAULTSIGBUS, similar to x86 when MEMORYFAILURE is not configured. Also print unexpected fault flags, for easier debugging.

Note that VMFAULTHWPOISONLARGE is not expected, because s390 cannot support swap entries on other levels than PTE level.

Affected Software

4 affected componentsFixes available
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel>=6.6<6.6.44
Linux Linux kernel>=6.7<6.9.12
Linux Linux kernel>=6.10<6.10.2

Event History

Jul 29, 2024
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
Description
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedySeverityWeaknessAffected Software
Dec 19, 2024
Data Sourced
via Ubuntu·12:31 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-41021?

CVE-2024-41021 has a medium severity level due to its potential impact on handling memory faults in the Linux kernel on s390 architecture.

2

How do I fix CVE-2024-41021?

To mitigate CVE-2024-41021, update your Linux kernel to one of the patched versions such as 5.10.223-1, 5.10.226-1, 6.1.119-1, or newer.

3

What systems are affected by CVE-2024-41021?

CVE-2024-41021 affects Linux kernel versions prior to the specified fixed releases, primarily on the s390 architecture.

4

Is CVE-2024-41021 present in all Linux kernel versions?

No, CVE-2024-41021 is specific to certain Linux kernel versions on the s390 architecture and doesn't apply to all Linux distributions.

5

What impact does CVE-2024-41021 have on system performance?

CVE-2024-41021 can potentially affect system stability and memory management on affected s390 systems if not addressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203