Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-39474— mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于vmalloc在使用__GFP_NOFAIL调用时可能返回null。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.22% · P13

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 9376130c390a76fac2788a5d6e1a149017b4ab50< 198a80833e3421d4c9820a4ae907120adf598c91 affected
9376130c390a76fac2788a5d6e1a149017b4ab50< c55d3564ad25ce87ab7cc6af251f9574faebd8da affected
9376130c390a76fac2788a5d6e1a149017b4ab50< 758678b65164b2158fc1de411092191cb3c394d4 affected
9376130c390a76fac2788a5d6e1a149017b4ab50< 8e0545c83d672750632f46e3f9ad95c48c91a0fc affected
5.17 affected
< 5.17 unaffected
6.1.95≤ 6.1.* unaffected
6.6.34≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-39474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commit a421ef303008 ("mm: allow !GFP_KERNEL allocations for kvmalloc") includes support for __GFP_NOFAIL, but it presents a conflict with commit dd544141b9eb ("vmalloc: back off when the current task is OOM-killed"). A possible scenario is as follows: process-a __vmalloc_node_range(GFP_KERNEL | __GFP_NOFAIL) __vmalloc_area_node() vm_area_alloc_pages() --> oom-killer send SIGKILL to process-a if (fatal_signal_pending(current)) break; --> return NULL; To fix this, do not check fatal_signal_pending() in vm_area_alloc_pages() if __GFP_NOFAIL set. This issue occurred during OPLUS KASAN TEST. Below is part of the log -> oom-killer sends signal to process [65731.222840] [ T1308] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=/,mems_allowed=0,global_oom,task_memcg=/apps/uid_10198,task=gs.intelligence,pid=32454,uid=10198 [65731.259685] [T32454] Call trace: [65731.259698] [T32454] dump_backtrace+0xf4/0x118 [65731.259734] [T32454] show_stack+0x18/0x24 [65731.259756] [T32454] dump_stack_lvl+0x60/0x7c [65731.259781] [T32454] dump_stack+0x18/0x38 [65731.259800] [T32454] mrdump_common_die+0x250/0x39c [mrdump] [65731.259936] [T32454] ipanic_die+0x20/0x34 [mrdump] [65731.260019] [T32454] atomic_notifier_call_chain+0xb4/0xfc [65731.260047] [T32454] notify_die+0x114/0x198 [65731.260073] [T32454] die+0xf4/0x5b4 [65731.260098] [T32454] die_kernel_fault+0x80/0x98 [65731.260124] [T32454] __do_kernel_fault+0x160/0x2a8 [65731.260146] [T32454] do_bad_area+0x68/0x148 [65731.260174] [T32454] do_mem_abort+0x151c/0x1b34 [65731.260204] [T32454] el1_abort+0x3c/0x5c [65731.260227] [T32454] el1h_64_sync_handler+0x54/0x90 [65731.260248] [T32454] el1h_64_sync+0x68/0x6c [65731.260269] [T32454] z_erofs_decompress_queue+0x7f0/0x2258 --> be->decompressed_pages = kvcalloc(be->nr_pages, sizeof(struct page *), GFP_KERNEL | __GFP_NOFAIL); kernel panic by NULL pointer dereference. erofs assume kvmalloc with __GFP_NOFAIL never return NULL. [65731.260293] [T32454] z_erofs_runqueue+0xf30/0x104c [65731.260314] [T32454] z_erofs_readahead+0x4f0/0x968 [65731.260339] [T32454] read_pages+0x170/0xadc [65731.260364] [T32454] page_cache_ra_unbounded+0x874/0xf30 [65731.260388] [T32454] page_cache_ra_order+0x24c/0x714 [65731.260411] [T32454] filemap_fault+0xbf0/0x1a74 [65731.260437] [T32454] __do_fault+0xd0/0x33c [65731.260462] [T32454] handle_mm_fault+0xf74/0x3fe0 [65731.260486] [T32454] do_mem_abort+0x54c/0x1b34 [65731.260509] [T32454] el0_da+0x44/0x94 [65731.260531] [T32454] el0t_64_sync_handler+0x98/0xb4 [65731.260553] [T32454] el0t_64_sync+0x198/0x19c
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于vmalloc在使用__GFP_NOFAIL调用时可能返回null。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 9376130c390a76fac2788a5d6e1a149017b4ab50 ~ 198a80833e3421d4c9820a4ae907120adf598c91 -
Linux Linux 5.17 -

II. Public POCs for CVE-2024-39474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-39474

登录查看更多情报信息。

Patches & Fixes for CVE-2024-39474 (1)

Other References for CVE-2024-39474 (3)

Same Patch Batch · Linux · 2024-07-05 · 14 CVEs total

CVE-2024-39480 8.4 HIGH kdb: Fix buffer overflow during tab-complete
CVE-2024-39482 7.8 HIGH bcache: fix variable length array abuse in btree_iter
CVE-2024-39481 7.8 HIGH media: mc: Fix graph walk in media_pipeline_start
CVE-2024-39479 7.8 HIGH drm/i915/hwmon: Get rid of devm
CVE-2024-39478 7.8 HIGH crypto: starfive - Do not free stack buffer
CVE-2024-39477 7.8 HIGH mm/hugetlb: do not call vma_add_reservation upon ENOMEM
CVE-2024-39472 7.3 HIGH xfs: fix log recovery buffer allocation for the legacy h_size fixup
CVE-2024-39483 7.1 HIGH KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked
CVE-2024-39485 media: v4l: async: Properly re-initialise notifier entry in unregister
CVE-2024-39484 mmc: davinci: Don't strip remove function when driver is builtin
CVE-2024-39476 md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
CVE-2024-39475 fbdev: savage: Handle err return when savagefb_check_var failed
CVE-2024-39473 ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension

IV. Related Vulnerabilities

V. Comments for CVE-2024-39474

No comments yet


Leave a comment