Executive brief
A vulnerability exists in the Linux kernel's memory management system on x86 processors. The issue occurs when the system handles specific memory mapping operations (Copy-on-Write), which can lead to the kernel failing to properly track or release memory resources. This could allow a local user to cause a system crash or trigger memory leaks, potentially impacting the stability and availability of the server.
Technical details
A vulnerability in the x86/mm/pat component of the Linux kernel arises from improper handling of VM_PAT in Copy-on-Write (COW) mappings. The root cause is that follow_phys() fails to reliably recover the correct Page Frame Number (PFN) and cachemode when Page Table Entries (PTEs) are replaced by anonymous folios during write faults. This failure triggers WARN_ON_ONCE() in untrack_pfn() and track_pfn_copy(), and prevents memtype_free() from being called correctly, leading to potential memory leaks. An attacker with local access can exploit this by triggering COW on specific memory mappings, such as those used by io_uring. Patches have been released across multiple stable kernel branches to update follow_phys() and ensure proper PFN fallback.
Affected products
- Linux Linux Kernel 6.9-rc1, 6.9-rc2, and earlier versions
Timeline
- 2024-04-03: patched: Initial patch submitted by David Hildenbrand
- 2024-05-19: disclosed: CVE-2024-35877 published
References
- https://git.kernel.org/stable/c/04c35ab3bdae7fefbd7c7a7355f29fa03a035221
- https://git.kernel.org/stable/c/09e6bb53217bf388a0d2fd7fb21e74ab9dffc173
- https://git.kernel.org/stable/c/1341e4b32e1fb1b0acd002ccd56f07bd32f2abc6
- https://git.kernel.org/stable/c/51b7841f3fe84606ec0bd8da859d22e05e5419ec
- https://git.kernel.org/stable/c/7cfee26d1950250b14c5cb0a37b142f3fcc6396a
- https://git.kernel.org/stable/c/97e93367e82752e475a33839a80b33bdbef1209f
- https://git.kernel.org/stable/c/c2b2430b48f3c9eaccd2c3d2ad75bb540d4952f4