CVE-2024-41074: cachefiles: Set object to close if ondemand_id < 0 in copen
In the Linux kernel, the following vulnerability has been resolved:
cachefiles: Set object to close if ondemandid < 0 in copen
If copen is maliciously called in the user mode, it may delete the request corresponding to the random id. And the request may have not been read yet.
Note that when the object is set to reopen, the open request will be done with the still reopen state in above case. As a result, the request corresponding to this object is always skipped in selectreq function, so the read request is never completed and blocks other process.
Fix this issue by simply set object to close if its id < 0 in copen.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41074?
CVE-2024-41074 is considered a high-severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2024-41074?
To remediate CVE-2024-41074, update to the specified patched versions of the Linux kernel provided in the affected software list.
Which Linux kernel versions are affected by CVE-2024-41074?
CVE-2024-41074 affects Linux kernel versions up to and including 5.10.226-1.
Can CVE-2024-41074 be exploited remotely?
CVE-2024-41074 requires malicious calls from user mode, indicating that exploitation is not typically remote.
Are there any recommended mitigations for CVE-2024-41074?
The most effective mitigation for CVE-2024-41074 is to ensure all systems are updated to the secure versions of the Linux kernel.