{ "dataType": "CVE_RECORD", "cveMetadata": { "cveId": "CVE-2024-27393", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-02-25T13:47:42.677Z", "datePublished": "2024-05-09T16:37:07.973Z", "dateUpdated": "2026-08-05T11:29:27.055Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:29:27.055Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen-netfront: Add missing skb_mark_for_recycle\n\nNotice that skb_mark_for_recycle() is introduced later than fixes tag in\ncommit 6a5bcd84e886 (\"page_pool: Allow drivers to hint on SKB recycling\").\n\nIt is believed that fixes tag were missing a call to page_pool_release_page()\nbetween v5.9 to v5.14, after which is should have used skb_mark_for_recycle().\nSince v6.6 the call page_pool_release_page() were removed (in\ncommit 535b9c61bdef (\"net: page_pool: hide page_pool_release_page()\")\nand remaining callers converted (in commit 6bfef2ec0172 (\"Merge branch\n'net-page_pool-remove-page_pool_release_page'\")).\n\nThis leak became visible in v6.8 via commit dba1b8a7ab68 (\"mm/page_pool: catch\npage_pool memory leaks\")." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The defect is in the xen-netfront RX refill/release path, driven entirely by packets arriving from the network; every inbound frame causes a page_pool page to be released outside the pool, in NAPI context before any socket demux or firewall decision. Any remote host that can route a packet to the guest reaches the vulnerable code.\nAC:L - There is no race, no memory-layout requirement, and no state the attacker cannot influence — the mishandling is deterministic for every single received packet, and the amplifying `check_pages_enabled` gate is on by default via CONFIG_INIT_ON_ALLOC_DEFAULT_ON on mainstream distributions. Simply sending traffic triggers it reliably.\nPR:N - The leak occurs in the driver receive path before any authentication, socket lookup, or filtering, so an entirely unauthenticated remote sender triggers it. No account, session, or local foothold on the guest is required.\nUI:N - No victim action is needed; the vulnerable path executes automatically whenever the guest's network interface receives frames. The interface is up and receiving by definition on any networked Xen guest.\nS:U - The leaked pages and the stalled page_pool are guest kernel resources, and the pool is created with .flags = 0 so no DMA/IOMMU mappings are left dangling; grant references are properly ended before the skb is handed up. Impact stays within the guest's own security authority, with no crossing into the hypervisor or dom0.\nC:N - There is no out-of-bounds or use-after-free read — pages are either quarantined by bad_page() or freed normally, and pp_magic aliases page->lru which is overwritten before reuse. No kernel data is disclosed to the attacker.\nI:N - Nothing is written out of bounds or after free; the only state affected is the page_pool's own inflight accounting and pages being withheld from the allocator. There is no write primitive and no path to control-flow hijacking.\nA:H - On any kernel with check_pages_enabled (CONFIG_DEBUG_VM, debug_pagealloc, or the widely shipped init_on_alloc/init_on_free hardening defaults), free_pages_prepare() rejects each RX page so 4 KB is permanently lost per received packet — an unbounded, remotely driven memory exhaustion leading to OOM kill and system death, plus tainting dmesg floods. Even without that gate, every device teardown/resume permanently leaks the page_pool with an endlessly rearming work item and \"stalled pool shutdown\" warnings." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/xen-netfront.c" ], "versions": [ { "version": "6c5aa6fc4defc2a0977a2c59e4710d50fa1e834c", "lessThan": "4143b9479caa29bb2380f3620dcbe16ea84eb3b1", "status": "affected", "versionType": "git" }, { "version": "6c5aa6fc4defc2a0977a2c59e4710d50fa1e834c", "lessThan": "7c1250796b6c262b505a46192f4716b8c6a6a8c6", "status": "affected", "versionType": "git" }, { "version": "6c5aa6fc4defc2a0977a2c59e4710d50fa1e834c", "lessThan": "27aa3e4b3088426b7e34584274ad45b5afaf7629", "status": "affected", "versionType": "git" }, { "version": "6c5aa6fc4defc2a0977a2c59e4710d50fa1e834c", "lessThan": "c8b7b2f158d9d4fb89cd2f68244af154f7549bb4", "status": "affected", "versionType": "git" }, { "version": "6c5aa6fc4defc2a0977a2c59e4710d50fa1e834c", "lessThan": "037965402a010898d34f4e35327d22c0a95cd51f", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/xen-netfront.c" ], "versions": [ { "version": "5.9", "status": "affected" }, { "version": "0", "lessThan": "5.9", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.154", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.85", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.26", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.5", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "5.15.154" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.1.85" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.6.26" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.8.5" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/4143b9479caa29bb2380f3620dcbe16ea84eb3b1" }, { "url": "https://git.kernel.org/stable/c/7c1250796b6c262b505a46192f4716b8c6a6a8c6" }, { "url": "https://git.kernel.org/stable/c/27aa3e4b3088426b7e34584274ad45b5afaf7629" }, { "url": "https://git.kernel.org/stable/c/c8b7b2f158d9d4fb89cd2f68244af154f7549bb4" }, { "url": "https://git.kernel.org/stable/c/037965402a010898d34f4e35327d22c0a95cd51f" } ], "title": "xen-netfront: Add missing skb_mark_for_recycle", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "lang": "en", "description": "CWE-noinfo Not enough information" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "NONE" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2024-05-31T18:36:32.425649Z", "id": "CVE-2024-27393", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-11-04T18:49:42.053Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T00:34:52.268Z" }, "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/4143b9479caa29bb2380f3620dcbe16ea84eb3b1", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/7c1250796b6c262b505a46192f4716b8c6a6a8c6", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/27aa3e4b3088426b7e34584274ad45b5afaf7629", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/c8b7b2f158d9d4fb89cd2f68244af154f7549bb4", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/037965402a010898d34f4e35327d22c0a95cd51f", "tags": [ "x_transferred" ] }, { "url": "http://xenbits.xen.org/xsa/advisory-457.html", "tags": [ "x_transferred" ] }, { "url": "http://www.openwall.com/lists/oss-security/2024/05/08/4", "tags": [ "x_transferred" ] } ] } ] }, "dataVersion": "5.2" }