PT-2024-33777 · Linux+8 · Linux Kernel+8
Published
2024-08-25
·
Updated
2026-03-14
·
CVE-2024-49935
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
The Linux kernel has a resolved vulnerability where the kernel occasionally crashes in cpumask clear cpu(), which is called within exit round robin(), due to a misalignment in memory address calculation when executing clear bit(nr, addr) with nr set to 0xffffffff. This leads to access to an invalid memory address. The issue is related to the ACPI: PAD component.
Recommendations:
To fix this issue, ensure that tsk in cpu[tsk index] != -1 before calling cpumask clear cpu() in exit round robin(), just as it is done in round robin cpu(). Update to Linux kernel version 6.6.58 or later to resolve the issue.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu