CVE-2024-50199

MEDIUM

Linux Kernel - Memory Leak via HugeTLB Page Handling in swapoff

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: skip HugeTLB pages for unuse_vma I got a bad pud error and lost a 1GB HugeTLB when calling swapoff. The problem can be reproduced by the following steps: 1. Allocate an anonymous 1GB HugeTLB and some other anonymous memory. 2. Swapout the above anonymous memory. 3. run swapoff and we will get a bad pud error in kernel message: mm/pgtable-generic.c:42: bad pud 00000000743d215d(84000001400000e7) We can tell that pud_clear_bad is called by pud_none_or_clear_bad in unuse_pud_range() by ftrace. And therefore the HugeTLB pages will never be freed because we lost it from page table. We can skip HugeTLB pages for unuse_vma to fix it.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (24)
linux/Kernel 2.6.36 - 5.4.285linux
linux/Kernel 5.11.0 - 5.15.169linux
linux/Kernel 5.16.0 - 6.1.114linux
linux/Kernel 5.5.0 - 5.10.228linux
linux/Kernel 6.2.0 - 6.6.58linux
linux/Kernel 6.7.0 - 6.11.5linux
Linux/Linux < 2.6.36
Linux/Linux 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f - 417d5838ca73c6331ae2fe692fab6c25c00d9a0b
Linux/Linux 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f - 6ec0fe3756f941f42f8c57156b8bdf2877b2ebaf
Linux/Linux 0fe6e20b9c4c53b3e97096ee73a0857f60aad43f - 7528c4fb1237512ee18049f852f014eba80bbe8d
... and 14 more
Published Nov 08, 2024
Tracked Since Feb 18, 2026