Junglewise Threat Intelligence

CVE-2024-47745: Linux Kernel W^X bypass in remap_file_pages

CVE-2024-47745 · Severity: high · CVSS 7.8 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security flaw in the Linux kernel's memory management system could allow a local attacker to bypass security protections that prevent memory from being both writable and executable at the same time. This protection, often called W^X, is a critical defense against malware and exploits. By bypassing this, an attacker could more easily execute malicious code on a compromised system, potentially leading to full system takeover.

Technical details

A vulnerability exists in the remap_file_pages() system call handler in the Linux kernel. The handler calls do_mmap() directly without invoking the security_mmap_file() Linux Security Module (LSM) hook. If a process has the READ_IMPLIES_EXEC personality set, calling remap_file_pages() on read-write (RW) pages can result in them being remapped as read-write-execute (RWX). This allows a local attacker to bypass W^X (Write XOR Execute) policies enforced by security frameworks like SELinux. The fix involves adding the missing security_mmap_file() hook call to the syscall handler.

Affected products

  • Linux Linux Kernel up to 6.11.2

Timeline

  • 2024-10-21: disclosed
  • 2024-10-21: advisory

References

Related threats