CVE-2024-42250

Source
https://cve.org/CVERecord?id=CVE-2024-42250
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42250.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-42250
Downstream
Related
Published
2024-08-07T15:14:33Z
Modified
2026-08-12T03:51:23Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
cachefiles: add missing lock protection when polling
Details

In the Linux kernel, the following vulnerability has been resolved:

cachefiles: add missing lock protection when polling

Add missing lock protection in poll routine when iterating xarray, otherwise:

Even with RCU read lock held, only the slot of the radix tree is ensured to be pinned there, while the data structure (e.g. struct cachefiles_req) stored in the slot has no such guarantee. The poll routine will iterate the radix tree and dereference cachefiles_req accordingly. Thus RCU read lock is not adequate in this case and spinlock is needed here.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42250.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0e19a18f998dcabe8be590e0b39660a1f230209b
Fixed
97cfd5e20ddc2e33e16ce369626ce76c9a475fd7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
18943864342705fa18dd4e6b8d608491fec81f6e
Fixed
6bb6bd3dd6f382dfd36220d4b210a0c77c066651
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b817e22b2e91257ace32a6768c3c003faeaa1c5c
Fixed
8eadcab7f3dd809edbe5ae20533ff843dfea3a07
Fixed
cf5bb09e742a9cf6349127e868329a8f69b7a014

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42250.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.9.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42250.json"