CVE-2024-49873: mm/filemap: fix filemap_get_folios_contig THP panic
In the Linux kernel, the following vulnerability has been resolved:
mm/filemap: fix filemapgetfolioscontig THP panic
Patch series "memfd-pin huge page fixes".
Fix multiple bugs that occur when using memfdpinfolios with hugetlb pages and THP. The hugetlb bugs only bite when the page is not yet faulted in when memfdpinfolios is called. The THP bug bites when the starting offset passed to memfdpinfolios is not huge page aligned. See the commit messages for details.
This patch (of 5):
memfdpinfolios on memory backed by THP panics if the requested start offset is not huge page aligned:
BUG: kernel NULL pointer dereference, address: 0000000000000036 RIP: 0010:filemapgetfolioscontig+0xdf/0x290 RSP: 0018:ffffc9002092fbe8 EFLAGS: 00010202 RAX: 0000000000000002 RBX: 0000000000000002 RCX: 0000000000000002
The fault occurs here, because xasload returns a folio with value 2:
filemapgetfolioscontig() for (folio = xasload(&xas); folio && xas.xaindex <= end; folio = xasnext(&xas)) { ... if (!foliotryget(folio)) <-- BOOM
"2" is an xarray sibling entry. We get it because memfdpinfolios does not round the indices passed to filemapgetfolioscontig to huge page boundaries for THP, so we load from the middle of a huge page range see a sibling. (It does round for hugetlbfs, at the isfilehugepages test).
To fix, if the folio is a sibling, then return the next index as the starting point for the next call to filemapgetfolioscontig.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49873?
CVE-2024-49873 has a low severity rating as it affects specific conditions in the Linux kernel that can lead to a panic.
How do I fix CVE-2024-49873?
To fix CVE-2024-49873, update to a version of the Linux kernel later than 6.11.3 where the vulnerability has been patched.
Which Linux kernel versions are affected by CVE-2024-49873?
CVE-2024-49873 affects Linux kernel versions from 6.11 to 6.11.3 inclusive.
What type of vulnerability is CVE-2024-49873?
CVE-2024-49873 is a memory management vulnerability affecting file mapping functionality in the Linux kernel.
Is CVE-2024-49873 exploitable remotely?
CVE-2024-49873 is not known to be remotely exploitable, as it requires specific local conditions related to memory management.