CVE-2024-27007
MEDIUMLinux Kernel 6.8-6.8.8 - Use-After-Free in userfaultfd UFFDIO_MOVE
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: change src_folio after ensuring it's unpinned in UFFDIO_MOVE Commit d7a08838ab74 ("mm: userfaultfd: fix unexpected change to src_folio when UFFDIO_MOVE fails") moved the src_folio->{mapping, index} changing to after clearing the page-table and ensuring that it's not pinned. This avoids failure of swapout+migration and possibly memory corruption. However, the commit missed fixing it in the huge-page case.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/
Scores
CVSS v3
5.5
EPSS
0.0023
EPSS Percentile
13.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (9)
linux/Kernel
6.8.0 - 6.8.8linux
Linux/Linux
< 6.8
Linux/Linux
6.8
Linux/Linux
6.8.8 - 6.8.*
Linux/Linux
6.9
Linux/Linux
adef440691bab824e39c1b17382322d195e1fab0 - c0205eaf3af9f5db14d4b5ee4abacf4a583c3c50
Linux/Linux
adef440691bab824e39c1b17382322d195e1fab0 - df5f6e683e7f21a15d8be6e7a0c7a46436963ebe
linux/linux_kernel
6.9 rc1 (4 CPE variants)
linux/linux_kernel
6.8 - 6.8.8
Published
May 01, 2024
Tracked Since
Feb 18, 2026