Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-50133— LoongArch: Don't crash in stack_top() for tasks without vDSO

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于LoongArch架构中,任务可能在没有vDSO映射的情况下调用stack_top函数,从而引发空指针取消引用,导致系统崩溃。

AI Predicted 5.5 Difficulty: Trivial EPSS 0.22% · P13

Possible ATT&CK Techniques 1 AI

T1498.003

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 803b0fc5c3f2baa6e54978cd576407896f789b08< a67d4a02bf43e15544179895ede7d5f97b84b550 affected
803b0fc5c3f2baa6e54978cd576407896f789b08< a94c197d4d749954dfaa37e907fcc8c04e4aad7e affected
803b0fc5c3f2baa6e54978cd576407896f789b08< 041cc3860b06770357876d1114d615333b0fbf31 affected
803b0fc5c3f2baa6e54978cd576407896f789b08< 134475a9ab8487527238d270639a8cb74c10aab2 affected
5.19 affected
< 5.19 unaffected
6.1.115≤ 6.1.* unaffected
6.6.59≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-50133

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LoongArch: Don't crash in stack_top() for tasks without vDSO
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Don't crash in stack_top() for tasks without vDSO Not all tasks have a vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL vdso pointer and crash. This can for example happen when using kunit: [<9000000000203874>] stack_top+0x58/0xa8 [<90000000002956cc>] arch_pick_mmap_layout+0x164/0x220 [<90000000003c284c>] kunit_vm_mmap_init+0x108/0x12c [<90000000003c1fbc>] __kunit_add_resource+0x38/0x8c [<90000000003c2704>] kunit_vm_mmap+0x88/0xc8 [<9000000000410b14>] usercopy_test_init+0xbc/0x25c [<90000000003c1db4>] kunit_try_run_case+0x5c/0x184 [<90000000003c3d54>] kunit_generic_run_threadfn_adapter+0x24/0x48 [<900000000022e4bc>] kthread+0xc8/0xd4 [<9000000000200ce8>] ret_from_kernel_thread+0xc/0xa4
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于LoongArch架构中,任务可能在没有vDSO映射的情况下调用stack_top函数,从而引发空指针取消引用,导致系统崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 803b0fc5c3f2baa6e54978cd576407896f789b08 ~ a67d4a02bf43e15544179895ede7d5f97b84b550 -
Linux Linux 5.19 -

II. Public POCs for CVE-2024-50133

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-50133

登录查看更多情报信息。

Patches & Fixes for CVE-2024-50133 (3)

Same Patch Batch · Linux · 2024-11-05 · 50 CVEs total

CVE-2024-50106 9.8 CRITICAL nfsd: fix race between laundromat and free_stateid
CVE-2024-50113 8.8 HIGH firewire: core: fix invalid port index for parent device
CVE-2024-50115 8.4 HIGH KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
CVE-2024-50125 8.0 HIGH Bluetooth: SCO: Fix UAF on sco_sock_timeout
CVE-2024-50124 8.0 HIGH Bluetooth: ISO: Fix UAF on iso_sock_timeout
CVE-2024-50132 7.8 HIGH tracing/probes: Fix MAX_TRACE_ARGS limit handling
CVE-2023-52920 7.8 HIGH bpf: support non-r10 register spill/fill to/from stack in precision tracking
CVE-2024-50091 7.8 HIGH dm vdo: don't refer to dedupe_context after releasing it
CVE-2024-50101 7.8 HIGH iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices
CVE-2024-50114 7.8 HIGH KVM: arm64: Unregister redistributor for failed vCPU creation
CVE-2024-50127 7.8 HIGH net: sched: fix use-after-free in taprio_change()
CVE-2024-50126 7.8 HIGH net: sched: use RCU read-side critical section in taprio_dump()
CVE-2024-50128 7.8 HIGH net: wwan: fix global oob in wwan_rtnl_policy
CVE-2024-50130 7.8 HIGH netfilter: bpf: must hold reference on net namespace
CVE-2024-50090 7.8 HIGH drm/xe/oa: Fix overflow in oa batch buffer
CVE-2024-50094 7.5 HIGH sfc: Don't invoke xdp_do_flush() from netpoll.
CVE-2024-50095 7.5 HIGH RDMA/mad: Improve handling of timed out WRs of mad agent
CVE-2024-50096 7.3 HIGH nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error
CVE-2024-50099 7.3 HIGH arm64: probes: Remove broken LDR (literal) uprobe support
CVE-2024-50131 7.3 HIGH tracing: Consider the NULL character when validating the event length

Showing top 20 of 50 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-50133

No comments yet


Leave a comment