CVE-2024-53138 (GCVE-0-2024-53138)
Vulnerability from cvelistv5
Published
2024-12-04 14:20
Modified
2026-08-05 11:44
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e_ktls_tx_handle_resync_dump_comp()), only put_page() is used. This is an issue when using pages from large folios: the get_page() references are stored on the folio page while the page_ref_inc() references are stored directly in the given page. On release the folio page will be dereferenced too many times. This was found while doing kTLS testing with sendfile() + ZC when the served file was read from NFS on a kernel with NFS large folios support (commit 49b29a573da8 ("nfs: add support for large folios")).
Impacted products
Vendor Product Version
Linux Linux Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Version: 84d1bb2b139e0184b1754aa1b5776186b475fce8
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:29:40.765Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_tx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "a0ddb20a748b122ea86003485f7992fa5e84cc95",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "ffad2ac8c859c1c1a981fe9c4f7ff925db684a43",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "c7b97f9e794d8e2bbaa50e1d6c230196fd214b5e",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "69fbd07f17b0fdaf8970bc705f5bf115c297839d",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "93a14620b97c911489a5b008782f3d9b0c4aeff4",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "2723e8b2cbd486cb96e5a61b22473f7fd62e18df",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            },
            {
              "lessThan": "dd6e972cc5890d91d6749bb48e3912721c4e4b25",
              "status": "affected",
              "version": "84d1bb2b139e0184b1754aa1b5776186b475fce8",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_tx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "lessThan": "5.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.287",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.231",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.174",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.119",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.63",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.287",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.231",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.174",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.119",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.63",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.10",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: kTLS, Fix incorrect page refcounting\n\nThe kTLS tx handling code is using a mix of get_page() and\npage_ref_inc() APIs to increment the page reference. But on the release\npath (mlx5e_ktls_tx_handle_resync_dump_comp()), only put_page() is used.\n\nThis is an issue when using pages from large folios: the get_page()\nreferences are stored on the folio page while the page_ref_inc()\nreferences are stored directly in the given page. On release the folio\npage will be dereferenced too many times.\n\nThis was found while doing kTLS testing with sendfile() + ZC when the\nserved file was read from NFS on a kernel with NFS large folios support\n(commit 49b29a573da8 (\"nfs: add support for large folios\"))."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable resync/DUMP path is entered only when a TCP segment is retransmitted on a kTLS-offloaded connection (`priv_tx-\u003eexpected_seq != seq`), and retransmission behavior is dictated entirely by the remote TLS peer\u0027s ACK/SACK behavior. A remote client of an mlx5e kTLS-offloaded TLS server reaches this code purely by sending network traffic, with no local access.\nAC:L - Once a client requests a sendfile()-served object, forcing retransmissions by dropping segments or withholding ACKs is trivially and repeatedly achievable, and the refcount over-decrement is deterministic (n=3 for the default 1500-byte MTU with 4K pages) rather than racy. No memory layout or timing condition outside the attacker\u0027s control must be won.\nPR:N - A public TLS/HTTPS endpoint accepts connections from anyone; no credentials, account, or local privileges are needed to open a connection, request a file, and manipulate the TCP ACK stream. The attacker acts purely as an ordinary remote TLS client.\nUI:N - The attacker drives the entire sequence \u2014 connect, request data, suppress ACKs \u2014 with no action required from any local user or administrator beyond the server already running its normal kTLS-offloaded workload.\nS:U - The corruption is of kernel page-cache refcounts and kernel memory, all within the host kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The folio refcount underflow frees an in-use page-cache folio that is still in the address_space and still referenced by TLS record frags and the retransmit queue; once the physical page is reallocated, its new contents (other tenants\u0027 file data, anonymous memory, or kernel objects) can be transmitted back over the attacker\u0027s own TLS connection, giving a broad memory-disclosure primitive.\nI:H - The same premature free gives a write primitive \u2014 page-cache writeback and continued DMA/TLS use write into memory that has been reallocated to other kernel objects, which is the classic UAF heap-spray path to control-flow hijack. The tail page\u0027s raw `_refcount` is also left permanently corrupted.\nA:H - Refcount underflow on a live folio trips `VM_BUG_ON_FOLIO`/`bad_page()` and frees memory that is still in use, producing oopses, page-allocator corruption, and kernel panic; the attacker can repeat this at will over many connections."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:44:01.599Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a0ddb20a748b122ea86003485f7992fa5e84cc95"
        },
        {
          "url": "https://git.kernel.org/stable/c/ffad2ac8c859c1c1a981fe9c4f7ff925db684a43"
        },
        {
          "url": "https://git.kernel.org/stable/c/c7b97f9e794d8e2bbaa50e1d6c230196fd214b5e"
        },
        {
          "url": "https://git.kernel.org/stable/c/69fbd07f17b0fdaf8970bc705f5bf115c297839d"
        },
        {
          "url": "https://git.kernel.org/stable/c/93a14620b97c911489a5b008782f3d9b0c4aeff4"
        },
        {
          "url": "https://git.kernel.org/stable/c/2723e8b2cbd486cb96e5a61b22473f7fd62e18df"
        },
        {
          "url": "https://git.kernel.org/stable/c/dd6e972cc5890d91d6749bb48e3912721c4e4b25"
        }
      ],
      "title": "net/mlx5e: kTLS, Fix incorrect page refcounting",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-53138",
    "datePublished": "2024-12-04T14:20:43.395Z",
    "dateReserved": "2024-11-19T17:17:24.996Z",
    "dateUpdated": "2026-08-05T11:44:01.599Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…