CVE-2024-42233

LOW

Linux Kernel 6.9-6.9.9 - Use-After-Free in filemap_fault_recheck_pte_none

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: filemap: replace pte_offset_map() with pte_offset_map_nolock() The vmf->ptl in filemap_fault_recheck_pte_none() is still set from handle_pte_fault(). But at the same time, we did a pte_unmap(vmf->pte). After a pte_unmap(vmf->pte) unmap and rcu_read_unlock(), the page table may be racily changed and vmf->ptl maybe fails to protect the actual page table. Fix this by replacing pte_offset_map() with pte_offset_map_nolock(). As David said, the PTL pointer might be stale so if we continue to use it infilemap_fault_recheck_pte_none(), it might trigger UAF. Also, if the PTL fails, the issue fixed by commit 58f327f2ce80 ("filemap: avoid unnecessary major faults in filemap_fault()") might reappear.

Scores

CVSS v3 3.3
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (8)
linux/Kernel 6.9.0 - 6.9.10linux
Linux/Linux < 6.9
Linux/Linux 58f327f2ce80f9c7b4a70e9cf017ae8810d44a20 - 24be02a42181f0707be0498045c4c4b13273b16d
Linux/Linux 58f327f2ce80f9c7b4a70e9cf017ae8810d44a20 - 6a6c2aec1a89506595801b4cf7e8eef035f33748
Linux/Linux 6.10
Linux/Linux 6.9
Linux/Linux 6.9.10 - 6.9.*
linux/linux_kernel 6.9 - 6.9.10
Published Aug 07, 2024
Tracked Since Feb 18, 2026