PT-2024-27188 · Linux+6 · Linux Kernel+6

Published

2024-04-22

·

Updated

2026-03-13

·

CVE-2024-36881

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the userfaultfd feature in the Linux kernel, where the unregister process did not properly remove write-protect bits from page table entries when a userfaultfd was closed. This could lead to leftover write-protect bits being observable by the user, although it is hoped to be harmless. The change is important after a recent page-table-check patch, as it ensures sanity checks on userfaultfd write-protect bits without virtual memory area context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-03055
CVE-2024-36881
ECHO-02AB-A485-9BB2
INFSA-2024_9315
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1897
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu