CVE-2024-41932

MEDIUM

Linux Kernel 6.2-6.12.4 - Denial of Service via sched_setaffinity Race Condition

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: sched: fix warning in sched_setaffinity Commit 8f9ea86fdf99b added some logic to sched_setaffinity that included a WARN when a per-task affinity assignment races with a cpuset update. Specifically, we can have a race where a cpuset update results in the task affinity no longer being a subset of the cpuset. That's fine; we have a fallback to instead use the cpuset mask. However, we have a WARN set up that will trigger if the cpuset mask has no overlap at all with the requested task affinity. This shouldn't be a warning condition; its trivial to create this condition. Reproduced the warning by the following setup: - $PID inside a cpuset cgroup - another thread repeatedly switching the cpuset cpus from 1-2 to just 1 - another thread repeatedly setting the $PID affinity (via taskset) to 2

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 8.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 6.2.0 - 6.12.5linux
Linux/Linux < 6.2
Linux/Linux 6.12.5 - 6.12.*
Linux/Linux 6.13
Linux/Linux 6.2
Linux/Linux 8f9ea86fdf99b81458cc21fc1c591fcd4a0fa1f4 - 5c3fb75f538cfcb886f6dfeb497d99fc2f263ee6
Linux/Linux 8f9ea86fdf99b81458cc21fc1c591fcd4a0fa1f4 - 70ee7947a29029736a1a06c73a48ff37674a851b
linux/linux_kernel 6.13 rc1 (2 CPE variants)
linux/linux_kernel 6.2 - 6.12.5
Published Jan 11, 2025
Tracked Since Feb 18, 2026