CVE-2024-38610 (GCVE-0-2024-38610)
Vulnerability from cvelistv5
Published
2024-06-19 13:56
Modified
2026-08-05 11:33
Summary
In the Linux kernel, the following vulnerability has been resolved: drivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map() Patch series "mm: follow_pte() improvements and acrn follow_pte() fixes". Patch #1 fixes a bunch of issues I spotted in the acrn driver. It compiles, that's all I know. I'll appreciate some review and testing from acrn folks. Patch #2+#3 improve follow_pte(), passing a VMA instead of the MM, adding more sanity checks, and improving the documentation. Gave it a quick test on x86-64 using VM_PAT that ends up using follow_pte(). This patch (of 3): We currently miss handling various cases, resulting in a dangerous follow_pte() (previously follow_pfn()) usage. (1) We're not checking PTE write permissions. Maybe we should simply always require pte_write() like we do for pin_user_pages_fast(FOLL_WRITE)? Hard to tell, so let's check for ACRN_MEM_ACCESS_WRITE for now. (2) We're not rejecting refcounted pages. As we are not using MMU notifiers, messing with refcounted pages is dangerous and can result in use-after-free. Let's make sure to reject them. (3) We are only looking at the first PTE of a bigger range. We only lookup a single PTE, but memmap->len may span a larger area. Let's loop over all involved PTEs and make sure the PFN range is actually contiguous. Reject everything else: it couldn't have worked either way, and rather made use access PFNs we shouldn't be accessing.
Impacted products
Vendor Product Version
Linux Linux Version: b9c43aa0b18da5619aac347d54cb67fe30d1f884
Version: 8a6e85f75a83d16a71077e41f2720c691f432002
Version: 8a6e85f75a83d16a71077e41f2720c691f432002
Version: 8a6e85f75a83d16a71077e41f2720c691f432002
Version: 8a6e85f75a83d16a71077e41f2720c691f432002
Version: 8a6e85f75a83d16a71077e41f2720c691f432002
Version: 149d5fb7e0124c3763e92edd1fde19417f4d2d09
Version: 02098ac42b7ff055ec72cd083ee1eb0a23481a19
Version: 5.15.33   
Version: 5.16.19   
Version: 5.17.2   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-38610",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-24T18:14:59.732296Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-24T18:15:07.284Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T04:12:25.993Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/5c6705aa47b5b78d7ad36fea832bb69caa5bf49a"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/afeb0e69627695f759fc73c39c1640dbf8649b32"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/e873f36ec890bece26ecce850e969917bceebbb6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/3d6586008f7b638f91f3332602592caa8b00b559"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/virt/acrn/mm.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "5c6705aa47b5b78d7ad36fea832bb69caa5bf49a",
              "status": "affected",
              "version": "b9c43aa0b18da5619aac347d54cb67fe30d1f884",
              "versionType": "git"
            },
            {
              "lessThan": "afeb0e69627695f759fc73c39c1640dbf8649b32",
              "status": "affected",
              "version": "8a6e85f75a83d16a71077e41f2720c691f432002",
              "versionType": "git"
            },
            {
              "lessThan": "e873f36ec890bece26ecce850e969917bceebbb6",
              "status": "affected",
              "version": "8a6e85f75a83d16a71077e41f2720c691f432002",
              "versionType": "git"
            },
            {
              "lessThan": "4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4",
              "status": "affected",
              "version": "8a6e85f75a83d16a71077e41f2720c691f432002",
              "versionType": "git"
            },
            {
              "lessThan": "2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb",
              "status": "affected",
              "version": "8a6e85f75a83d16a71077e41f2720c691f432002",
              "versionType": "git"
            },
            {
              "lessThan": "3d6586008f7b638f91f3332602592caa8b00b559",
              "status": "affected",
              "version": "8a6e85f75a83d16a71077e41f2720c691f432002",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "149d5fb7e0124c3763e92edd1fde19417f4d2d09",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02098ac42b7ff055ec72cd083ee1eb0a23481a19",
              "versionType": "git"
            },
            {
              "lessThan": "5.15.161",
              "status": "affected",
              "version": "5.15.33",
              "versionType": "semver"
            },
            {
              "lessThan": "5.17",
              "status": "affected",
              "version": "5.16.19",
              "versionType": "semver"
            },
            {
              "lessThan": "5.18",
              "status": "affected",
              "version": "5.17.2",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/virt/acrn/mm.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "lessThan": "5.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.161",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.93",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.161",
                  "versionStartIncluding": "5.15.33",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.93",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.33",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.12",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.3",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.16.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.17.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()\n\nPatch series \"mm: follow_pte() improvements and acrn follow_pte() fixes\".\n\nPatch #1 fixes a bunch of issues I spotted in the acrn driver.  It\ncompiles, that\u0027s all I know.  I\u0027ll appreciate some review and testing from\nacrn folks.\n\nPatch #2+#3 improve follow_pte(), passing a VMA instead of the MM, adding\nmore sanity checks, and improving the documentation.  Gave it a quick test\non x86-64 using VM_PAT that ends up using follow_pte().\n\n\nThis patch (of 3):\n\nWe currently miss handling various cases, resulting in a dangerous\nfollow_pte() (previously follow_pfn()) usage.\n\n(1) We\u0027re not checking PTE write permissions.\n\nMaybe we should simply always require pte_write() like we do for\npin_user_pages_fast(FOLL_WRITE)? Hard to tell, so let\u0027s check for\nACRN_MEM_ACCESS_WRITE for now.\n\n(2) We\u0027re not rejecting refcounted pages.\n\nAs we are not using MMU notifiers, messing with refcounted pages is\ndangerous and can result in use-after-free. Let\u0027s make sure to reject them.\n\n(3) We are only looking at the first PTE of a bigger range.\n\nWe only lookup a single PTE, but memmap-\u003elen may span a larger area.\nLet\u0027s loop over all involved PTEs and make sure the PFN range is\nactually contiguous. Reject everything else: it couldn\u0027t have worked\neither way, and rather made use access PFNs we shouldn\u0027t be accessing."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The flaw is reached only through `ioctl(ACRN_IOCTL_SET_MEMSEG)` on the `/dev/acrn_hsm` misc device from a local process in the ACRN Service VM. No network or adjacent-network protocol handler reaches `acrn_vm_ram_map()`.\nAC:L - The attacker fully controls both halves of the trigger: it chooses which file to `mmap()` to create the VM_PFNMAP VMA (read-only mapping, refcounted-page-backed VMA, or a VMA whose PFNs are non-contiguous) and supplies `vma_base`/`len`/`attr` directly to the ioctl. There is no race, no timing window, and no dependence on memory layout the attacker cannot influence \u2014 the single-PTE lookup and the missing `pte_write()` check fail identically on every attempt.\nPR:L - `acrn_dev_ioctl()` contains no `capable()` or `CAP_*` gate at all, so the only barrier is the permission bits on `/dev/acrn_hsm`; like `/dev/kvm`, this HSM node is commonly made group-accessible to the deprivileged device-model account in ACRN Service VM deployments, putting the full `CREATE_VM` + `SET_MEMSEG` sequence in reach of an ordinary local user.\nUI:N - The attacker performs the entire sequence itself \u2014 open the device, create a VM, mmap a PFNMAP region, issue the ioctl. No victim has to mount, open, click, or otherwise act.\nS:U - The resources actually compromised are host physical pages and kernel objects belonging to the same Linux kernel that contains the vulnerable driver, and the attacker already owns the User VM it maps them into, so the gain is a conventional local kernel privilege escalation rather than a crossing into a different security authority.\nC:H - Because only the first PTE is resolved and the rest of `memmap-\u003elen` is mapped as `PFN_PHYS(pfn)+i`, the attacker\u0027s guest receives EPT read access to host physical pages entirely unrelated to the VMA, and the unrejected refcounted pages remain readable after being freed and reallocated to other kernel objects \u2014 an arbitrary host-memory disclosure primitive.\nI:H - The missing `pte_write()` check lets a read-only host PTE be published to the guest with `ACRN_MEM_ACCESS_WRITE`, and the unbounded PFN range plus the use-after-free on refcounted pages give the guest write access to arbitrary host physical memory and to freed-then-reallocated slab/page contents, which is a direct path to kernel control-flow hijacking.\nA:H - Writing through stale EPT mappings of freed refcounted pages, or into host physical pages that were never part of the mapping, corrupts live kernel data structures and reliably produces oopses and panics of the Service VM host."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:33:09.136Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5c6705aa47b5b78d7ad36fea832bb69caa5bf49a"
        },
        {
          "url": "https://git.kernel.org/stable/c/afeb0e69627695f759fc73c39c1640dbf8649b32"
        },
        {
          "url": "https://git.kernel.org/stable/c/e873f36ec890bece26ecce850e969917bceebbb6"
        },
        {
          "url": "https://git.kernel.org/stable/c/4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4"
        },
        {
          "url": "https://git.kernel.org/stable/c/2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb"
        },
        {
          "url": "https://git.kernel.org/stable/c/3d6586008f7b638f91f3332602592caa8b00b559"
        }
      ],
      "title": "drivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-38610",
    "datePublished": "2024-06-19T13:56:12.083Z",
    "dateReserved": "2024-06-18T19:36:34.942Z",
    "dateUpdated": "2026-08-05T11:33:09.136Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/5c6705aa47b5b78d7ad36fea832bb69caa5bf49a\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/afeb0e69627695f759fc73c39c1640dbf8649b32\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/e873f36ec890bece26ecce850e969917bceebbb6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/3d6586008f7b638f91f3332602592caa8b00b559\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T04:12:25.993Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-38610\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-24T18:14:59.732296Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-24T18:15:04.471Z\"}}], \"cna\": {\"title\": \"drivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"b9c43aa0b18da5619aac347d54cb67fe30d1f884\", \"lessThan\": \"5c6705aa47b5b78d7ad36fea832bb69caa5bf49a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8a6e85f75a83d16a71077e41f2720c691f432002\", \"lessThan\": \"afeb0e69627695f759fc73c39c1640dbf8649b32\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8a6e85f75a83d16a71077e41f2720c691f432002\", \"lessThan\": \"e873f36ec890bece26ecce850e969917bceebbb6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8a6e85f75a83d16a71077e41f2720c691f432002\", \"lessThan\": \"4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8a6e85f75a83d16a71077e41f2720c691f432002\", \"lessThan\": \"2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8a6e85f75a83d16a71077e41f2720c691f432002\", \"lessThan\": \"3d6586008f7b638f91f3332602592caa8b00b559\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"149d5fb7e0124c3763e92edd1fde19417f4d2d09\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"02098ac42b7ff055ec72cd083ee1eb0a23481a19\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.15.33\", \"lessThan\": \"5.15.161\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.16.19\", \"lessThan\": \"5.17\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.17.2\", \"lessThan\": \"5.18\", \"versionType\": \"semver\"}], \"programFiles\": [\"drivers/virt/acrn/mm.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.18\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.18\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.161\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.93\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.33\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.12\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/virt/acrn/mm.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/5c6705aa47b5b78d7ad36fea832bb69caa5bf49a\"}, {\"url\": \"https://git.kernel.org/stable/c/afeb0e69627695f759fc73c39c1640dbf8649b32\"}, {\"url\": \"https://git.kernel.org/stable/c/e873f36ec890bece26ecce850e969917bceebbb6\"}, {\"url\": \"https://git.kernel.org/stable/c/4c4ba3cf3a15ccfbaf787d0296fa42cdb00da9b4\"}, {\"url\": \"https://git.kernel.org/stable/c/2c8d6e24930b8ef7d4a81787627c559ae0e0d3bb\"}, {\"url\": \"https://git.kernel.org/stable/c/3d6586008f7b638f91f3332602592caa8b00b559\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()\\n\\nPatch series \\\"mm: follow_pte() improvements and acrn follow_pte() fixes\\\".\\n\\nPatch #1 fixes a bunch of issues I spotted in the acrn driver.  It\\ncompiles, that\u0027s all I know.  I\u0027ll appreciate some review and testing from\\nacrn folks.\\n\\nPatch #2+#3 improve follow_pte(), passing a VMA instead of the MM, adding\\nmore sanity checks, and improving the documentation.  Gave it a quick test\\non x86-64 using VM_PAT that ends up using follow_pte().\\n\\n\\nThis patch (of 3):\\n\\nWe currently miss handling various cases, resulting in a dangerous\\nfollow_pte() (previously follow_pfn()) usage.\\n\\n(1) We\u0027re not checking PTE write permissions.\\n\\nMaybe we should simply always require pte_write() like we do for\\npin_user_pages_fast(FOLL_WRITE)? Hard to tell, so let\u0027s check for\\nACRN_MEM_ACCESS_WRITE for now.\\n\\n(2) We\u0027re not rejecting refcounted pages.\\n\\nAs we are not using MMU notifiers, messing with refcounted pages is\\ndangerous and can result in use-after-free. Let\u0027s make sure to reject them.\\n\\n(3) We are only looking at the first PTE of a bigger range.\\n\\nWe only lookup a single PTE, but memmap-\u003elen may span a larger area.\\nLet\u0027s loop over all involved PTEs and make sure the PFN range is\\nactually contiguous. Reject everything else: it couldn\u0027t have worked\\neither way, and rather made use access PFNs we shouldn\u0027t be accessing.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.161\", \"versionStartIncluding\": \"5.15.33\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.93\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.33\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.12\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.3\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.16.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.17.2\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-23T15:49:27.986Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-38610\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-23T15:49:27.986Z\", \"dateReserved\": \"2024-06-18T19:36:34.942Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-06-19T13:56:12.083Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…