PT-2024-35543 · Linux+5 · Linux Kernel+5

Published

2024-11-05

·

Updated

2026-05-26

·

CVE-2024-53079

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.65
Description The issue concerns a problem with the Linux kernel's memory management, specifically with the handling of Transparent Huge Pages (THP) deferred split queues. Recent changes in the kernel have increased pressure on these queues, revealing long-standing races and causing list corruption, "Bad page state" errors, and other issues. The problem arises from the lack of proper locking and unqueueing of THP folios from the deferred split list, particularly during swapout and memcg (memory control group) operations. This can lead to corruption of the memcg's list and other safety issues. The estimated number of potentially affected devices is not specified, and there is no information about real-world incidents where this issue was exploited.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.65 or later. As a temporary workaround, consider disabling the folio unqueue deferred split() function until a patch is available. Restrict access to the vulnerable mem cgroup swapout() and mem cgroup move account() functions to minimize the risk of exploitation. Avoid using the folio->memcg data variable in the affected code paths until the issue is resolved.

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2024-17891
ALT-PU-2025-12647
AZL-53867
AZL-53924
BDU:2025-15075
CVE-2024-53079
ECHO-8308-4504-0675
MGASA-2024-0392
MGASA-2024-0393
OESA-2025-1204
OESA-2025-1205
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu