CVE-2024-41033
MEDIUMLinux Kernel 6.8-6.9.10 - Denial of Service via cachestat RCU Read Section
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: cachestat: do not flush stats in recency check syzbot detects that cachestat() is flushing stats, which can sleep, in its RCU read section (see [1]). This is done in the workingset_test_recent() step (which checks if the folio's eviction is recent). Move the stat flushing step to before the RCU read section of cachestat, and skip stat flushing during the recency check. [1]: https://lore.kernel.org/cgroups/[email protected]/
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0029
EPSS Percentile
21.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (10)
linux/Kernel
6.8.0 - 6.9.10linux
Linux/Linux
< 6.8
Linux/Linux
6.10
Linux/Linux
6.8
Linux/Linux
6.9.10 - 6.9.*
Linux/Linux
68849411ce9eb55d00cef48504dcb35baca4b37e - e2f7c76758be16f1dc32c5a82270d4f6649eedab
Linux/Linux
b006847222623ac3cda8589d15379eac86a2bcb7 - 1d1ba14e00d290b1ed616ed78c8c49bf897ce390
Linux/Linux
b006847222623ac3cda8589d15379eac86a2bcb7 - 5a4d8944d6b1e1aaaa83ea42c116b520b4ed0394
linux/linux_kernel
6.10 rc1 (7 CPE variants)
linux/linux_kernel
6.8 - 6.9.10
Published
Jul 29, 2024
Tracked Since
Feb 18, 2026