{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-57875", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-01-11T14:45:42.023Z", "datePublished": "2025-01-11T14:49:01.655Z", "dateUpdated": "2026-08-05T11:46:43.350Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:46:43.350Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: RCU protect disk->conv_zones_bitmap\n\nEnsure that a disk revalidation changing the conventional zones bitmap\nof a disk does not cause invalid memory references when using the\ndisk_zone_is_conv() helper by RCU protecting the disk->conv_zones_bitmap\npointer.\n\ndisk_zone_is_conv() is modified to operate under the RCU read lock and\nthe function disk_set_conv_zones_bitmap() is added to update a disk\nconv_zones_bitmap pointer using rcu_replace_pointer() with the disk\nzone_wplugs_lock spinlock held.\n\ndisk_free_zone_resources() is modified to call\ndisk_update_zone_resources() with a NULL bitmap pointer to free the disk\nconv_zones_bitmap. disk_set_conv_zones_bitmap() is also used in\ndisk_update_zone_resources() to set the new (revalidated) bitmap and\nfree the old one." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable helper is reached only through the local block I/O submission path (`submit_bio`/`blk_mq_submit_bio` → `blk_zone_plug_bio`) and zone-management ioctls (`BLKRESETZONE`/`BLKFINISHZONE`) against a zoned block device node or a filesystem mounted on it. There is no network protocol handler in the path; the racing revalidation is a local block-layer/driver operation.\nAC:L - The attacker fully controls the reader side and can drive `disk_zone_is_conv()` continuously and indefinitely with a cheap write/zone-reset loop, so the race can be retried without limit at no cost until a revalidation (admin rescan, `BLKRRPART`, DM table reload, or a device-driven SCSI capacity-change unit attention / NVMe namespace-changed AEN, all of which recur in normal operation) lands in the window. No specific memory layout or victim state that the attacker cannot influence is required.\nPR:L - An ordinary unprivileged local user only needs write access to the zoned block device or to a filesystem on it (common for containers given a ZNS namespace, storage hosts with SMR disks, and Android/embedded systems running f2fs on zoned storage) to keep the vulnerable read path hot. No capability check guards `blk_zone_plug_bio()` on the submission path.\nUI:N - Triggering requires only the attacker's own I/O against the zoned device concurrently with a revalidation event; no victim has to open a file, mount a filesystem, or take any other action.\nS:U - The freed bitmap and the corrupted decision logic are both kernel block-layer state, so the impact stays within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - `test_bit()` on the freed bitmap reads memory that may already have been reallocated to another kernel object, and the resulting bit value is observable to the attacker through the differing I/O behavior (zone append accepted vs. `-EIO`), yielding a use-after-free read oracle over recycled kernel heap contents.\nI:H - A stale/freed bitmap can make a sequential-write-required zone be classified as conventional, causing writes to bypass zone write plugging entirely and be issued out of order to the device — corrupting on-disk data on the zoned device — and the use-after-free read is the kind of memory-safety defect that is treated as exploitable for further corruption.\nA:H - Dereferencing the freed bitmap can oops the kernel (kvmalloc/vmalloc-backed bitmaps for large zone counts become unmapped on free, and KASAN/DEBUG_PAGEALLOC builds fault immediately), and even without a fault the misclassification produces write-ordering failures that force I/O errors and filesystem shutdown on the zoned device." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "block/blk-zoned.c", "include/linux/blkdev.h" ], "versions": [ { "version": "dd291d77cc90eb6a86e9860ba8e6e38eebd57d12", "lessThan": "493326c4f10cc71a42c27fdc97ce112182ee4cbc", "status": "affected", "versionType": "git" }, { "version": "dd291d77cc90eb6a86e9860ba8e6e38eebd57d12", "lessThan": "d7cb6d7414ea1b33536fa6d11805cb8dceec1f97", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "block/blk-zoned.c", "include/linux/blkdev.h" ], "versions": [ { "version": "6.10", "status": "affected" }, { "version": "0", "lessThan": "6.10", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.5", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.13", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.12.5" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.13" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/493326c4f10cc71a42c27fdc97ce112182ee4cbc" }, { "url": "https://git.kernel.org/stable/c/d7cb6d7414ea1b33536fa6d11805cb8dceec1f97" } ], "title": "block: RCU protect disk->conv_zones_bitmap", "x_generator": { "engine": "bippy-1.2.0" } } } }