CVE-2024-41033

MEDIUM

Linux Kernel 6.8-6.9.10 - Denial of Service via cachestat RCU Read Section

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cachestat: do not flush stats in recency check syzbot detects that cachestat() is flushing stats, which can sleep, in its RCU read section (see [1]). This is done in the workingset_test_recent() step (which checks if the folio's eviction is recent). Move the stat flushing step to before the RCU read section of cachestat, and skip stat flushing during the recency check. [1]: https://lore.kernel.org/cgroups/[email protected]/

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 21.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (10)
linux/Kernel 6.8.0 - 6.9.10linux
Linux/Linux < 6.8
Linux/Linux 6.10
Linux/Linux 6.8
Linux/Linux 6.9.10 - 6.9.*
Linux/Linux 68849411ce9eb55d00cef48504dcb35baca4b37e - e2f7c76758be16f1dc32c5a82270d4f6649eedab
Linux/Linux b006847222623ac3cda8589d15379eac86a2bcb7 - 1d1ba14e00d290b1ed616ed78c8c49bf897ce390
Linux/Linux b006847222623ac3cda8589d15379eac86a2bcb7 - 5a4d8944d6b1e1aaaa83ea42c116b520b4ed0394
linux/linux_kernel 6.10 rc1 (7 CPE variants)
linux/linux_kernel 6.8 - 6.9.10
Published Jul 29, 2024
Tracked Since Feb 18, 2026