CVE-2024-43834: xdp: fix invalid wait context of page_pool_destroy()

Published Aug 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

xdp: fix invalid wait context of pagepooldestroy()

If the driver uses a page pool, it creates a page pool with pagepoolcreate(). The reference count of page pool is 1 as default. A page pool will be destroyed only when a reference count reaches 0. pagepooldestroy() is used to destroy page pool, it decreases a reference count. When a page pool is destroyed, ->disconnect() is called, which is memallocatordisconnect(). This function internally acquires mutexlock().

If the driver uses XDP, it registers a memory model with xdprxqinforegmemmodel(). The xdprxqinforegmemmodel() internally increases a page pool reference count if a memory model is a page pool. Now the reference count is 2.

To destroy a page pool, the driver should call both pagepooldestroy() and xdpunregmemmodel(). The xdpunregmemmodel() internally calls pagepooldestroy(). Only pagepooldestroy() decreases a reference count.

If a driver calls pagepooldestroy() then xdpunregmemmodel(), we will face an invalid wait context warning. Because xdpunregmemmodel() calls pagepooldestroy() with rcureadlock(). The pagepooldestroy() internally acquires mutexlock().

Splat looks like: ============================= [ BUG: Invalid wait context ] 6.10.0-rc6+ #4 Tainted: G W ----------------------------- ethtool/1806 is trying to lock: ffffffff90387b90 (memidlock){+.+.}-{4:4}, at: memallocatordisconnect+0x73/0x150 other info that might help us debug this: context-{5:5} 3 locks held by ethtool/1806: stack backtrace: CPU: 0 PID: 1806 Comm: ethtool Tainted: G W 6.10.0-rc6+ #4 f916f41f172891c800f2fed Hardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021 Call Trace: <TASK> dumpstacklvl+0x7e/0xc0 lockacquire+0x1681/0x4de0 ? printk+0x64/0xe0 ? pfxmarklock.part.0+0x10/0x10 ? pfxlockacquire+0x10/0x10 lockacquire+0x1b3/0x580 ? memallocatordisconnect+0x73/0x150 ? wakeupklogd.part.0+0x16/0xc0 ? pfxlockacquire+0x10/0x10 ? dumpstacklvl+0x91/0xc0 mutexlock+0x15c/0x1690 ? memallocatordisconnect+0x73/0x150 ? pfxprbreadvalid+0x10/0x10 ? memallocatordisconnect+0x73/0x150 ? pfxllistaddbatch+0x10/0x10 ? consoleunlock+0x193/0x1b0 ? lockdephardirqson+0xbe/0x140 ? pfxmutexlock+0x10/0x10 ? ticknohztickstopped+0x16/0x90 ? irqworkqueuelocal+0x1e5/0x330 ? irqworkqueue+0x39/0x50 ? wakeupklogd.part.0+0x79/0xc0 ? memallocatordisconnect+0x73/0x150 memallocatordisconnect+0x73/0x150 ? pfxmemallocatordisconnect+0x10/0x10 ? markheldlocks+0xa5/0xf0 ? rcuiswatching+0x11/0xb0 pagepoolrelease+0x36e/0x6d0 pagepooldestroy+0xd7/0x440 xdpunregmemmodel+0x1a7/0x2a0 ? pfxxdpunregmemmodel+0x10/0x10 ? kfree+0x125/0x370 ? bnxtfreering.isra.0+0x2eb/0x500 ? bnxtfreemem+0x5ac/0x2500 xdprxqinfounreg+0x4a/0xd0 bnxtfreemem+0x1356/0x2500 bnxtclosenic+0xf0/0x3b0 ? pfxbnxtclosenic+0x10/0x10 ? ethnlparsebit+0x2c6/0x6d0 ? pfxnlavalidateparse+0x10/0x10 ? pfxethnlparsebit+0x10/0x10 bnxtsetfeatures+0x2a8/0x3e0 netdevupdatefeatures+0x4dc/0x1370 ? ethnlparsebitset+0x4ff/0x750 ? pfxethnlparsebitset+0x10/0x10 ? pfxnetdevupdatefeatures+0x10/0x10 ? markheldlocks+0xa5/0xf0 ? rawspinunlockirqrestore+0x42/0x70 ? pmruntimeresume+0x7d/0x110 ethnlsetfeatures+0x32d/0xa20

To fix this problem, it uses rhashtablelookupfast() instead of rhashtablelookup() with rcureadlock(). Using xa without rcureadlock() here is safe. xa is freed by xdpmemallocatorrcufree() and this is called by callrcu() of memxaremove(). The memxaremove() is called by pagepooldestroy() if a reference count reaches 0. The xa is already protected by the reference count mechanism well in the control plane. So removing rcureadlock() for pagepooldestroy() is safe.

Affected Software

10 affected componentsFixes available
Linux Linux kernel>=5.3.18<5.4
Linux Linux kernel>=5.4.5<5.5
Linux Linux kernel>=5.5<6.1.103
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft cbl2 kernel 5.15.180.1-1
Microsoft cbl2 kernel 5.15.180.1-1<5.15.176.3-1
5.15.176.3-1
Microsoft cbl2 kernel 5.15.176.3-1<5.15.176.3-1
5.15.176.3-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.15.176.3-1
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch xdp: fix invalid wait context of page_pool_destroy()
  5. Compensating control

    If possible, avoid using XDP/page-pool-based XDP memory models (i.e., do not register/unregister page-pool-backed memory models via xdp_rxq_info_reg_mem_model()/xdp_unreg_mem_model()) until the kernel fix is applied, to prevent triggering the invalid wait context warning.

Event History

Aug 17, 2024
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityAffected Software
Apr 29, 2025
Data Sourced
via Ubuntu·06:21 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·04:47 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·04:47 AM
Affected Software
Updated
via Microsoft·04:47 AM
SeverityAffected Software
Updated
via Microsoft·04:47 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2024-43834?

CVE-2024-43834 is classified as a low severity vulnerability in the Linux kernel.

2

How do I fix CVE-2024-43834?

To resolve CVE-2024-43834, update to the recommended versions of the affected Linux kernel packages.

3

Which Linux kernel versions are affected by CVE-2024-43834?

CVE-2024-43834 affects multiple versions of the Linux kernel, specifically versions below 5.10.226-1 and several versions between 5.4 and 6.10.3.

4

Is CVE-2024-43834 remotely exploitable?

CVE-2024-43834 does not appear to be remotely exploitable as it involves specific conditions related to page pool management.

5

What is the nature of the issue in CVE-2024-43834?

CVE-2024-43834 addresses an invalid wait context in the page_pool_destroy function of the Linux kernel's XDP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203