{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-49866", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-10-21T12:17:06.018Z", "datePublished": "2024-10-21T18:01:09.284Z", "dateUpdated": "2026-08-05T11:40:14.365Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:40:14.365Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Fix a race during cpuhp processing\n\nThere is another found exception that the \"timerlat/1\" thread was\nscheduled on CPU0, and lead to timer corruption finally:\n\n```\nODEBUG: init active (active state 0) object: ffff888237c2e108 object type: hrtimer hint: timerlat_irq+0x0/0x220\nWARNING: CPU: 0 PID: 426 at lib/debugobjects.c:518 debug_print_object+0x7d/0xb0\nModules linked in:\nCPU: 0 UID: 0 PID: 426 Comm: timerlat/1 Not tainted 6.11.0-rc7+ #45\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:debug_print_object+0x7d/0xb0\n...\nCall Trace:\n \n ? __warn+0x7c/0x110\n ? debug_print_object+0x7d/0xb0\n ? report_bug+0xf1/0x1d0\n ? prb_read_valid+0x17/0x20\n ? handle_bug+0x3f/0x70\n ? exc_invalid_op+0x13/0x60\n ? asm_exc_invalid_op+0x16/0x20\n ? debug_print_object+0x7d/0xb0\n ? debug_print_object+0x7d/0xb0\n ? __pfx_timerlat_irq+0x10/0x10\n __debug_object_init+0x110/0x150\n hrtimer_init+0x1d/0x60\n timerlat_main+0xab/0x2d0\n ? __pfx_timerlat_main+0x10/0x10\n kthread+0xb7/0xe0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x40\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n```\n\nAfter tracing the scheduling event, it was discovered that the migration\nof the \"timerlat/1\" thread was performed during thread creation. Further\nanalysis confirmed that it is because the CPU online processing for\nosnoise is implemented through workers, which is asynchronous with the\noffline processing. When the worker was scheduled to create a thread, the\nCPU may has already been removed from the cpu_online_mask during the offline\nprocess, resulting in the inability to select the right CPU:\n\nT1 | T2\n[CPUHP_ONLINE] | cpu_device_down()\nosnoise_hotplug_workfn() |\n | cpus_write_lock()\n | takedown_cpu(1)\n | cpus_write_unlock()\n[CPUHP_OFFLINE] |\n cpus_read_lock() |\n start_kthread(1) |\n cpus_read_unlock() |\n\nTo fix this, skip online processing if the CPU is already offline." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - Both halves of the race are driven purely through local file interfaces — enabling the osnoise/timerlat tracer via tracefs (`current_tracer`, `osnoise/cpus`) and cycling `/sys/devices/system/cpu/cpuN/online` — with no network- or peer-facing consumer of `osnoise_hotplug_workfn()`.\nAC:L - The attacker controls both sides of the race: keep timerlat registered so `osnoise_has_registered_instances()` passes, then repeatedly toggle a CPU offline/online so the deferred `osnoise_hotplug_work` is still blocked on `trace_types_lock`/`cpus_read_lock()` when `takedown_cpu()` clears the CPU from `cpu_online_mask`; the window is hit reliably by looping hotplug, and the required configs (`TIMERLAT_TRACER`, `HOTPLUG_CPU`) are standard in distro kernels.\nPR:L - No `capable()` check guards the path — access is governed only by file permissions on tracefs and the CPU-hotplug sysfs node, which are routinely relaxed via the tracefs `gid=` mount option for tracing groups, in privileged/`/sys`-rw containers, and on latency-tooling (rtla/HPC) hosts; additionally CPU offline/online cycles are generated without root by suspend/resume and hypervisor vCPU hotplug while an admin-started timerlat session runs.\nUI:N - The attacker drives the tracer enable and the CPU hotplug cycling directly in a loop; no victim must open a file, mount a filesystem, or take any other action.\nS:U - The corrupted objects — the per-CPU `hrtimer_cpu_base` timerqueue and a freed `task_struct` — live in the same kernel security authority as the triggering code; no VM, container, or IOMMU boundary is crossed.\nC:H - The misplaced timerlat kthread leaves `tlat->kthread` pointing at an exited, freed `task_struct` that `timerlat_irq()` dereferences via `wake_up_process()` from hardirq context, so freed slab contents are read and acted upon; combined with the corrupted hrtimer rbtree this is exploitable for kernel memory disclosure.\nI:H - `__hrtimer_init()` performs `memset(timer, 0, sizeof(struct hrtimer))` on an hrtimer still enqueued in CPU0's timerqueue, zeroing a live rb_node and the callback pointer, and the dangling `tlat->kthread` yields a use-after-free write into a reclaimed `task_struct` — memory corruption of a type leverageable for control-flow hijack via heap grooming.\nA:H - The bug reproduces as a `debug_print_object()` WARNING (\"init active object\" on `timerlat_irq`) and proceeds to timer corruption — a zeroed node left linked in the hrtimer rbtree plus a NULL `timer->function` invoked from hardirq — producing oops/panic or a hung timer subsystem, and an immediate panic under `panic_on_warn`/`panic_on_oops`." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "kernel/trace/trace_osnoise.c" ], "versions": [ { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "322920b53dc11f9c2b33397eb3ae5bc6a175b60d", "status": "affected", "versionType": "git" }, { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "ce25f33ba89d6eefef64157655d318444580fa14", "status": "affected", "versionType": "git" }, { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "a6e9849063a6c8f4cb2f652a437e44e3ed24356c", "status": "affected", "versionType": "git" }, { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "a0d9c0cd5856191e095cf43a2e141b73945b7716", "status": "affected", "versionType": "git" }, { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "f72b451dc75578f644a3019c1489e9ae2c14e6c4", "status": "affected", "versionType": "git" }, { "version": "c8895e271f7994a3ecb13b8a280e39aa53879545", "lessThan": "829e0c9f0855f26b3ae830d17b24aec103f7e915", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "kernel/trace/trace_osnoise.c" ], "versions": [ { "version": "5.14", "status": "affected" }, { "version": "0", "lessThan": "5.14", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.168", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.113", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.55", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.14", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11.3", "lessThanOrEqual": "6.11.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "5.15.168" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "6.1.113" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "6.6.55" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "6.10.14" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "6.11.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.14", "versionEndExcluding": "6.12" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/322920b53dc11f9c2b33397eb3ae5bc6a175b60d" }, { "url": "https://git.kernel.org/stable/c/ce25f33ba89d6eefef64157655d318444580fa14" }, { "url": "https://git.kernel.org/stable/c/a6e9849063a6c8f4cb2f652a437e44e3ed24356c" }, { "url": "https://git.kernel.org/stable/c/a0d9c0cd5856191e095cf43a2e141b73945b7716" }, { "url": "https://git.kernel.org/stable/c/f72b451dc75578f644a3019c1489e9ae2c14e6c4" }, { "url": "https://git.kernel.org/stable/c/829e0c9f0855f26b3ae830d17b24aec103f7e915" } ], "title": "tracing/timerlat: Fix a race during cpuhp processing", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-49866", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-10-22T13:47:35.638203Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-22T13:48:52.640Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:22:33.052Z" } } ] } }