mm/page_table_check: fix crash on ZONE_DEVICE
Published Jul 12, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Not all pages may apply to pgtable check. One example is ZONE_DEVICE pages: they map PFNs directly, and they don't allocate page_ext at all even if there's struct page around. One may reference devm_memremap_pages().
When both ZONE_DEVICE and page-table-check enabled, then try to map some dax memories, one can trigger kernel bug constantly now when the kernel was trying to inject some pfn maps on the dax device:
kernel BUG at mm/page_table_check.c:55!
While it's pretty legal to use set_pxx_at() for ZONE_DEVICE pages for page fault resolutions, skip all the checks if page_ext doesn't even exist in pgtable checker, which applies to ZONE_DEVICE but maybe more.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.17
Unaffected
- ≥ 0, < 5.17
- ≥ 6.1.96, ≤ 6.1.*
- 6.10
- ≥ 6.6.36, ≤ 6.6.*
- ≥ 6.9.7, ≤ 6.9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.17 · < 6.1.96
- ≥ 6.2 · < 6.6.36
- ≥ 6.7 · < 6.9.7
- 6.10
- 6.10
- 6.10
- 6.10
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2024-40948 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297532 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38835 Advisory
- https://git.kernel.org/stable/c/51897f99351fff7b57f4f141940fa93b4e90fd2b Patch
- https://git.kernel.org/stable/c/84d3549d54f5ff9fa3281257be3019386f51d1a0 Patch
- https://git.kernel.org/stable/c/8bb592c2eca8fd2bc06db7d80b38da18da4a2f43 Patch
- https://git.kernel.org/stable/c/dec2382247860d2134c8d41e103e26460c099629 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024071222-CVE-2024-40948-e1a6@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40948
- https://www.cve.org/CVERecord?id=CVE-2024-40948
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data