{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-35797", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-17T12:19:12.340Z", "datePublished": "2024-05-17T13:23:08.204Z", "dateUpdated": "2026-08-05T11:30:00.460Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:30:00.460Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: cachestat: fix two shmem bugs\n\nWhen cachestat on shmem races with swapping and invalidation, there\nare two possible bugs:\n\n1) A swapin error can have resulted in a poisoned swap entry in the\n shmem inode's xarray. Calling get_shadow_from_swap_cache() on it\n will result in an out-of-bounds access to swapper_spaces[].\n\n Validate the entry with non_swap_entry() before going further.\n\n2) When we find a valid swap entry in the shmem's inode, the shadow\n entry in the swapcache might not exist yet: swap IO is still in\n progress and we're before __remove_mapping; swapin, invalidation,\n or swapoff have removed the shadow from swapcache after we saw the\n shmem swap entry.\n\n This will send a NULL to workingset_test_recent(). The latter\n purely operates on pointer bits, so it won't crash - node 0, memcg\n ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a\n bogus test. In theory that could result in a false \"recently\n evicted\" count.\n\n Such a false positive wouldn't be the end of the world. But for\n code clarity and (future) robustness, be explicit about this case.\n\n Bail on get_shadow_from_swap_cache() returning NULL." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is reached only through the `cachestat(2)` syscall on a local file descriptor for a shmem/tmpfs mapping (memfd, /dev/shm, or any readable tmpfs file). There is no network or remote-peer path into `filemap_cachestat()`.\nAC:L - Once a poisoned swap entry exists in a shmem inode it persists until truncate, and every `cachestat()` call covering that index deterministically and repeatably performs the out-of-bounds `swapper_spaces[]` access; the attacker additionally controls both sides of the cachestat-vs-swapping/invalidation race and can drive unbounded shmem swap I/O (large tmpfs files plus memory pressure) to provoke the swapin error, which is routine on flash-backed embedded/IoT swap and network-backed swap in diskless/cloud deployments.\nPR:L - `cachestat(2)` performs only `fdget()` with no capability or permission check whatsoever in the affected versions, and any unprivileged user can create a shmem mapping via `memfd_create()` or `/dev/shm`. No elevated privileges or namespace tricks are needed.\nUI:N - The attacker triggers the flaw entirely from their own process with a single syscall on a file descriptor they already hold. No action by any other user or victim process is required.\nS:U - The out-of-bounds access, wild dereference and resulting oops are all confined to the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The read past the end of `swapper_spaces[]` yields an unvalidated non-pointer value that is dereferenced as a `struct address_space` and walked as an xarray, so the kernel reads memory at an address it never bounds-checked; the value derived from that walk feeds `workingset_test_recent()` whose outcome is reflected in the `nr_recently_evicted` field copied back to userspace, forming a kernel-memory disclosure oracle. This is an unbounded out-of-bounds read, not a read strictly limited to a few bytes.\nI:N - The faulty path only performs reads (`xa_load`), and the memcg reference taken in `workingset_test_recent()` is released on all paths, so no kernel memory is written or corrupted and no write or control-flow-hijack primitive is produced. The only integrity effect is an inaccurate statistics counter returned to the caller.\nA:H - The out-of-bounds `swapper_spaces[31]` value is almost always zero (or unmapped garbage), producing a NULL/wild pointer dereference and kernel oops inside an `rcu_read_lock()` critical section; the leaked RCU nesting on task death can escalate to RCU stalls and a system-wide hang, and `panic_on_oops` systems panic outright." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/filemap.c" ], "versions": [ { "version": "cf264e1329fb0307e044f7675849f9f38b44c11a", "lessThan": "b79f9e1ff27c994a4c452235ba09e672ec698e23", "status": "affected", "versionType": "git" }, { "version": "cf264e1329fb0307e044f7675849f9f38b44c11a", "lessThan": "d962f6c583458037dc7e529659b2b02b9dd3d94b", "status": "affected", "versionType": "git" }, { "version": "cf264e1329fb0307e044f7675849f9f38b44c11a", "lessThan": "24a0e73d544439bb9329fbbafac44299e548a677", "status": "affected", "versionType": "git" }, { "version": "cf264e1329fb0307e044f7675849f9f38b44c11a", "lessThan": "d5d39c707a4cf0bcc84680178677b97aa2cb2627", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/filemap.c" ], "versions": [ { "version": "6.5", "status": "affected" }, { "version": "0", "lessThan": "6.5", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.24", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.7.12", "lessThanOrEqual": "6.7.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.3", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.6.24" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.7.12" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.8.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/b79f9e1ff27c994a4c452235ba09e672ec698e23" }, { "url": "https://git.kernel.org/stable/c/d962f6c583458037dc7e529659b2b02b9dd3d94b" }, { "url": "https://git.kernel.org/stable/c/24a0e73d544439bb9329fbbafac44299e548a677" }, { "url": "https://git.kernel.org/stable/c/d5d39c707a4cf0bcc84680178677b97aa2cb2627" } ], "title": "mm: cachestat: fix two shmem bugs", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-787", "lang": "en", "description": "CWE-787 Out-of-bounds Write" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "LOW", "privilegesRequired": "NONE", "confidentialityImpact": "NONE" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2024-05-17T17:19:03.392959Z", "id": "CVE-2024-35797", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-11-12T16:52:46.185Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T03:21:47.505Z" }, "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/b79f9e1ff27c994a4c452235ba09e672ec698e23", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/d962f6c583458037dc7e529659b2b02b9dd3d94b", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/24a0e73d544439bb9329fbbafac44299e548a677", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/d5d39c707a4cf0bcc84680178677b97aa2cb2627", "tags": [ "x_transferred" ] } ] } ] } }