sched/eevdf: Prevent vlag from going out of bounds in reweight_eevdf()
Published May 20, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.23%
Description
It was possible to have pick_eevdf() return NULL, which then causes a NULL-deref. This turned out to be due to entity_eligible() returning falsely negative because of a s64 multiplcation overflow.
Specifically, reweight_eevdf() computes the vlag without considering the limit placed upon vlag as update_entity_lag() does, and then the scaling multiplication (remember that weight is 20bit fixed point) can overflow. This then leads to the new vruntime being weird which then causes the above entity_eligible() to go side-ways and claim nothing is eligible.
Thus limit the range of vlag accordingly.
All this was quite rare, but fatal when it does happen.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.6.4StatusaffectedConstraints<6.6.30
- Version
-
- Version 6.7StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.7
- Version 6.6.30StatusunaffectedConstraints<=6.6.*
- Version 6.8.9StatusunaffectedConstraints<=6.8.*
- Version 6.9StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.6.4 · < 6.6.30
- ≥ 6.7 · < 6.8.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-35985 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2281857 Issue Tracking
- https://git.kernel.org/stable/c/06f27e6d7bf0abf54488259ef36bbf0e1fccb35c Patch
- https://git.kernel.org/stable/c/1560d1f6eb6b398bddd80c16676776c0325fe5fe Patch
- https://git.kernel.org/stable/c/470d347b14b0ecffa9b39cf8f644fa2351db3efb Patch
- https://lore.kernel.org/linux-cve-announce/2024052018-CVE-2024-35985-8839@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-35985
- https://www.cve.org/CVERecord?id=CVE-2024-35985
Change history (0)
No recorded changes yet.