Bug 2329929 (CVE-2024-53105)
| Summary: | CVE-2024-53105 kernel: mm: page_alloc: move mlocked flag clearance into free_pages_prepare() | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dfreiber, drow, jburrell, rhel-process-autobot, vkumar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in the Linux kernel's memory management subsystem. When certain memory pages are freed while still marked as locked in memory, the kernel detects an inconsistent page state and permanently takes those pages out of service. A local user could exploit this vulnerability through specific memory operations to trigger kernel warnings and cause memory leaks, potentially leading to a denial of service (DoS).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2329949 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2024-12-02 14:02:07 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024120244-CVE-2024-53105-d978@gregkh/T This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:6966 https://access.redhat.com/errata/RHSA-2025:6966 |