CVE-2024-27007

MEDIUM

Linux Kernel 6.8-6.8.8 - Use-After-Free in userfaultfd UFFDIO_MOVE

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: change src_folio after ensuring it's unpinned in UFFDIO_MOVE Commit d7a08838ab74 ("mm: userfaultfd: fix unexpected change to src_folio when UFFDIO_MOVE fails") moved the src_folio->{mapping, index} changing to after clearing the page-table and ensuring that it's not pinned. This avoids failure of swapout+migration and possibly memory corruption. However, the commit missed fixing it in the huge-page case.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 6.8.0 - 6.8.8linux
Linux/Linux < 6.8
Linux/Linux 6.8
Linux/Linux 6.8.8 - 6.8.*
Linux/Linux 6.9
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - c0205eaf3af9f5db14d4b5ee4abacf4a583c3c50
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - df5f6e683e7f21a15d8be6e7a0c7a46436963ebe
linux/linux_kernel 6.9 rc1 (4 CPE variants)
linux/linux_kernel 6.8 - 6.8.8
Published May 01, 2024
Tracked Since Feb 18, 2026