Bug 2324645 (CVE-2024-50199) - CVE-2024-50199 kernel: mm/swapfile: skip HugeTLB pages for unuse_vma
Summary: CVE-2024-50199 kernel: mm/swapfile: skip HugeTLB pages for unuse_vma
Keywords:
Status: NEW
Alias: CVE-2024-50199
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2325162
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-11-08 13:50 UTC by OSIDB Bzimport
Modified: 2024-11-21 18:55 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-11-08 13:50:21 UTC
In the Linux kernel, the following vulnerability has been resolved:

mm/swapfile: skip HugeTLB pages for unuse_vma

I got a bad pud error and lost a 1GB HugeTLB when calling swapoff.  The
problem can be reproduced by the following steps:

 1. Allocate an anonymous 1GB HugeTLB and some other anonymous memory.
 2. Swapout the above anonymous memory.
 3. run swapoff and we will get a bad pud error in kernel message:

  mm/pgtable-generic.c:42: bad pud 00000000743d215d(84000001400000e7)

We can tell that pud_clear_bad is called by pud_none_or_clear_bad in
unuse_pud_range() by ftrace.  And therefore the HugeTLB pages will never
be freed because we lost it from page table.  We can skip HugeTLB pages
for unuse_vma to fix it.


Note You need to log in before you can comment on or make changes to this bug.