{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-35874", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-17T13:50:33.110Z", "datePublished": "2024-05-19T08:34:31.937Z", "dateUpdated": "2026-08-05T11:30:34.827Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:30:34.827Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naio: Fix null ptr deref in aio_complete() wakeup\n\nlist_del_init_careful() needs to be the last access to the wait queue\nentry - it effectively unlocks access.\n\nPreviously, finish_wait() would see the empty list head and skip taking\nthe lock, and then we'd return - but the completion path would still\nattempt to do the wakeup after the task_struct pointer had been\noverwritten." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is reached purely through the local AIO syscalls io_setup(2)/io_submit(2)/io_getevents(2); no network or adjacent-network interface processes data that reaches fs/aio.c. Exploitation requires the ability to execute code on the target system.\nAC:L - The attacker controls both sides of the race — a thread blocked in io_getevents() supplies the waiter, and a second thread deterministically drives aio_complete() on another CPU (e.g. IOCB_CMD_POLL armed on a pipe, or O_DIRECT block completions), and the sequence can be retried millions of times per second with CPU pinning. The bug was observed firing in ordinary production workloads, confirming the window is reachable without any condition outside the attacker's influence.\nPR:L - io_setup/io_submit/io_getevents are unprivileged syscalls with no capability, LSM, or namespace gate on the path through do_io_getevents() → read_events(); CONFIG_AIO is default y and enabled on virtually all deployments. Any local unprivileged user, including one inside a container, can reach the vulnerable code.\nUI:N - The entire attack is a self-contained sequence of syscalls issued by the attacker's own threads. No victim action, mount, or file open is needed.\nS:U - The corruption occurs in kernel memory and is exploited by a local user to attack the same kernel; there is no crossing of a VM, IOMMU, or other security-authority boundary. This is a standard kernel local privilege-escalation scope.\nC:H - This is a use-after-return on the waiter's kernel stack whose stale contents the attacker can groom with a follow-up syscall, and the resulting pointer is dereferenced by try_to_wake_up(), which reads p->__state, p->on_rq, p->on_cpu and task_cpu(p) from attacker-chosen kernel addresses. Per kernel scoring guidance, UAF-class corruption that can be steered into arbitrary kernel reads is High.\nI:H - try_to_wake_up() on the attacker-influenced pointer performs raw_spin_lock_irqsave(&p->pi_lock), WRITE_ONCE(p->__state, TASK_WAKING) and a runqueue enqueue with linked-list pointer stores, yielding a write primitive at an attacker-selected address, with the scheduler ultimately context-switching into a forged task_struct. That is memory corruption exploitable for control-flow hijack and privilege escalation.\nA:H - The reported and readily reproducible symptom is a NULL/wild pointer dereference in aio_complete()'s wakeup path, producing a kernel oops in interrupt-disabled context. Any unprivileged user can trigger this repeatedly to panic the machine." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/aio.c" ], "versions": [ { "version": "71eb6b6b0ba93b1467bccff57b5de746b09113d2", "lessThan": "9678bcc6234d83759fe091c197f5017a32b468da", "status": "affected", "versionType": "git" }, { "version": "71eb6b6b0ba93b1467bccff57b5de746b09113d2", "lessThan": "caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/aio.c" ], "versions": [ { "version": "6.8", "status": "affected" }, { "version": "0", "lessThan": "6.8", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.5", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.8.5" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da" }, { "url": "https://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd" } ], "title": "aio: Fix null ptr deref in aio_complete() wakeup", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CISA ADP Vulnrichment", "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-35874", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-05-28T19:39:02.782020Z" } } } ], "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-04T17:33:49.700Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T03:21:48.477Z" }, "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd", "tags": [ "x_transferred" ] } ] } ] } }