Executive brief
A security flaw in the Linux kernel's memory management system could allow a local attacker to bypass security protections that prevent memory from being both writable and executable at the same time. This protection, often called W^X, is a critical defense against malware and exploits. By bypassing this, an attacker could more easily execute malicious code on a compromised system, potentially leading to full system takeover.
Technical details
A vulnerability exists in the remap_file_pages() system call handler in the Linux kernel. The handler calls do_mmap() directly without invoking the security_mmap_file() Linux Security Module (LSM) hook. If a process has the READ_IMPLIES_EXEC personality set, calling remap_file_pages() on read-write (RW) pages can result in them being remapped as read-write-execute (RWX). This allows a local attacker to bypass W^X (Write XOR Execute) policies enforced by security frameworks like SELinux. The fix involves adding the missing security_mmap_file() hook call to the syscall handler.
Affected products
- Linux Linux Kernel up to 6.11.2
Timeline
- 2024-10-21: disclosed
- 2024-10-21: advisory
References
- https://git.kernel.org/stable/c/0f910dbf2f2a4a7820ba4bac7b280f7108aa05b1
- https://git.kernel.org/stable/c/3393fddbfa947c8e1fdcc4509226905ffffd8b89
- https://git.kernel.org/stable/c/49d3a4ad57c57227c3b0fd6cd4188b2a5ebd6178
- https://git.kernel.org/stable/c/ce14f38d6ee9e88e37ec28427b4b93a7c33c70d3
- https://git.kernel.org/stable/c/ea7e2d5e49c05e5db1922387b09ca74aa40f46e2
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html