Executive brief
A vulnerability in the Linux kernel's parallel data processing component (padata) can cause the system to crash during startup or operation. This occurs due to a mathematical error (division by zero) when the system attempts to manage multi-threaded tasks with specific configurations. An exploit would result in a complete system denial of service, requiring a reboot to recover.
Technical details
A divide-by-zero vulnerability exists in the padata_mt_helper() function within kernel/padata.c. The root cause is that the 'chunk_size' variable can be initialized to zero in padata_do_multithreaded() if the 'min_chunk' parameter in the padata_mt_job structure is set to zero by a caller. When this zero value is subsequently used in division operations within the helper function, it triggers a kernel panic (Oops: divide error). The fix ensures chunk_size is at least 1. This is reachable by local users with sufficient privileges to trigger multithreaded padata jobs, primarily impacting system availability.
Affected products
- Linux Linux Kernel 5.8 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.105, 6.2 to 6.6.46, 6.7 to 6.10.5
Timeline
- 2024-08-06: patched: Initial patch submitted by Waiman Long
- 2024-08-26: advisory: CVE-2024-43889 published
References
- https://git.kernel.org/stable/c/6d45e1c948a8b7ed6ceddb14319af69424db730c
- https://git.kernel.org/stable/c/8f5ffd2af7274853ff91d6cd62541191d9fbd10d
- https://git.kernel.org/stable/c/924f788c906dccaca30acab86c7124371e1d6f2c
- https://git.kernel.org/stable/c/a29cfcb848c31f22b4de6a531c3e1d68c9bfe09f
- https://git.kernel.org/stable/c/ab8b397d5997d8c37610252528edc54bebf9f6d3
- https://git.kernel.org/stable/c/da0ffe84fcc1627a7dff82c80b823b94236af905
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html