PT-2025-2980 · Linux+4 · Linux Kernel+4
Published
2024-12-11
·
Updated
2026-05-26
·
CVE-2024-53687
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.74
Description
The issue is related to the usage of IPIs in the
kfence protect page() function, which can trigger a warning when the irqs are disabled. The flush tlb kernel range() function may use IPIs to flush the TLBs of all cores, leading to potential inaccuracies when using kfence. The vulnerability has been resolved by fixing the IPIs usage in kfence protect page().Recommendations
For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the
kfence protect page() function until a patch is available. Restrict access to the vulnerable flush tlb kernel range() function to minimize the risk of exploitation. Avoid using the kfence feature in the affected kernel versions until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu