Executive brief
A vulnerability in the Linux kernel's device mapper component can cause the system to lock up or become unresponsive. This occurs when the system attempts to close a storage snapshot that contains a large number of recorded changes (exceptions). An attacker with local access could potentially exploit this to cause a denial-of-service, disrupting operations and system availability.
Technical details
A CPU lockup vulnerability exists in the Linux kernel's 'dm snapshot' component within the 'dm_exception_table_exit' function. The root cause is an improper locking mechanism (CWE-667) where a loop responsible for freeing snapshot exceptions fails to yield the CPU, leading to a soft lockup when processing a large number of entries. A local attacker can trigger this condition by closing a snapshot that has accumulated many exceptions. The fix involves adding 'cond_resched()' to the loop to allow the scheduler to run other tasks. Patches have been released across multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.8.y.
Affected products
- Linux Linux Kernel up to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3
Timeline
- 2024-03-20: patched: Initial patch committed to Linux kernel source
- 2024-05-17: disclosed: CVE-2024-35805 published
References
- https://git.kernel.org/stable/c/116562e804ffc9dc600adab6326dde31d72262c7
- https://git.kernel.org/stable/c/3d47eb405781cc5127deca9a14e24b27696087a1
- https://git.kernel.org/stable/c/5f4ad4d0b0943296287313db60b3f84df4aad683
- https://git.kernel.org/stable/c/6e7132ed3c07bd8a6ce3db4bb307ef2852b322dc
- https://git.kernel.org/stable/c/9759ff196e7d248bcf8386a7451d6ff8537a7d9c
- https://git.kernel.org/stable/c/e50f83061ac250f90710757a3e51b70a200835e2
- https://git.kernel.org/stable/c/e7d4cff57c3c43fdd72342c78d4138f509c7416e