CVE-2024-42241: mm/shmem: disable PMD-sized page cache if needed

Published Aug 7, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mm/shmem: disable PMD-sized page cache if needed

For shmem files, it's possible that PMD-sized page cache can't be supported by xarray. For example, 512MB page cache on ARM64 when the base page size is 64KB can't be supported by xarray. It leads to errors as the following messages indicate when this sort of xarray entry is split.

WARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xassplitalloc+0xf8/0x128 Modules linked in: binfmtmisc nftfibinet nftfibipv4 nftfibipv6 \ nftfib nftrejectinet nfrejectipv4 nfrejectipv6 nftreject \ nftct nftchainnat nfnat nfconntrack nfdefragipv6 nfdefragipv4 \ ipset rfkill nftables nfnetlink vfat fat virtioballoon drm fuse xfs \ libcrc32c crct10difce ghashce sha2ce sha256arm64 sha1ce virtionet \ netfailover virtioconsole virtioblk failover dimlib virtiommio CPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xassplitalloc+0xf8/0x128 lr : splithugepagetolisttoorder+0x1c4/0x720 sp : ffff8000882af5f0 x29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768 x26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858 x23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000 x17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000 x14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020 x11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0 x5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace: xassplitalloc+0xf8/0x128 splithugepagetolisttoorder+0x1c4/0x720 truncateinodepartialfolio+0xdc/0x160 shmemundorange+0x2bc/0x6a8 shmemfallocate+0x134/0x430 vfsfallocate+0x124/0x2e8 ksysfallocate+0x4c/0xa0 arm64sysfallocate+0x24/0x38 invokesyscall.constprop.0+0x7c/0xd8 doel0svc+0xb4/0xd0 el0svc+0x44/0x1d8 el0t64synchandler+0x134/0x150 el0t64sync+0x17c/0x180

Fix it by disabling PMD-sized page cache when HPAGEPMDORDER is larger than MAXPAGECACHEORDER. As Matthew Wilcox pointed, the page cache in a shmem file isn't represented by a multi-index entry and doesn't have this limitation when the xarry entry is split until commit 6b24ca4a1a8d ("mm: Use multi-index entries in the page cache").

Affected Software

5 affected componentsFixes available
Linux Linux kernel>=5.17<6.6.41
Linux Linux kernel>=6.7<6.9.10
debian/linux<=6.1.129-1, <=6.1.135-1
5.10.223-15.10.234-16.12.22-16.12.25-1
Microsoft azl3 kernel 6.6.35.1-5
Microsoft azl3 kernel 6.6.43.1-7

Event History

Aug 7, 2024
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
Description
Aug 16, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Dec 15, 2024
Data Sourced
via Ubuntu·12:32 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-42241?

CVE-2024-42241 has a high severity due to the potential impact on memory management and page caching in the Linux kernel.

2

How do I fix CVE-2024-42241?

To fix CVE-2024-42241, upgrade to the patched version of the Linux kernel listed in the vulnerability advisory.

3

Which versions of the Linux kernel are affected by CVE-2024-42241?

CVE-2024-42241 affects Linux kernel versions between 5.17 and 6.6.41, as well as versions between 6.7 and 6.9.10.

4

What systems are vulnerable to CVE-2024-42241?

Any systems running the affected versions of the Linux kernel, including various distributions that package the kernel, are vulnerable to CVE-2024-42241.

5

Is there a specific distribution that has the fix for CVE-2024-42241?

Yes, Debian has released specific kernel packages including versions 5.10.223-1, 5.10.226-1, and 6.12.12-1 to address CVE-2024-42241.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203