PT-2024-10463 · Linux+10 · Linux Kernel+10
Zach Okeefe
·
Published
2024-07-30
·
Updated
2025-09-29
·
CVE-2024-42131
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to an integer overflow in the dirty throttling logic of the Linux kernel's mm component. This occurs when the operator sets dirty limits to more than 16 TB, causing potential overflows and divisions by zero. The problem is root-only triggerable and can be mitigated by never allowing dirty limits to exceed a certain value. The
dirty bytes, dirty background bytes, dirty ratio, and dirty background ratio interfaces are affected, and the issue can be triggered when converting dirty limits from ratios to numbers of pages. The vulnerable functions include domain dirty limits(), node dirty limit(), dirty background bytes handler(), and dirty bytes handler() in mm/page-writeback.c. Exploitation of this issue may allow an attacker to execute arbitrary code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu