CVE-2024-41027

In the Linux kernel, the following vulnerability has been resolved: Fix userfaultfd_api to return EINVAL as expected Currently if we request a feature that is not set in the Kernel config we fail silently and return all the available features. However, the man page indicates we should return an EINVAL. We need to fix this issue since we can end up with a Kernel warning should a program request the feature UFFD_FEATURE_WP_UNPOPULATED on a kernel with the config not set with this feature. [ 200.812896] WARNING: CPU: 91 PID: 13634 at mm/memory.c:1660 zap_pte_range+0x43d/0x660 [ 200.820738] Modules linked in: [ 200.869387] CPU: 91 PID: 13634 Comm: userfaultfd Kdump: loaded Not tainted 6.9.0-rc5+ #8 [ 200.877477] Hardware name: Dell Inc. PowerEdge R6525/0N7YGH, BIOS 2.7.3 03/30/2022 [ 200.885052] RIP: 0010:zap_pte_range+0x43d/0x660
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc7:*:*:*:*:*:*

History

07 Oct 2025, 16:32

Type Values Removed Values Added
CWE NVD-CWE-Other
References () https://git.kernel.org/stable/c/14875fd5f9bcf60ac5518c63bfb676ade44aa7c6 - () https://git.kernel.org/stable/c/14875fd5f9bcf60ac5518c63bfb676ade44aa7c6 - Patch
References () https://git.kernel.org/stable/c/1723f04caacb32cadc4e063725d836a0c4450694 - () https://git.kernel.org/stable/c/1723f04caacb32cadc4e063725d836a0c4450694 - Patch
References () https://git.kernel.org/stable/c/519547760f16eae7803d2658d9524bc5ba7a20a7 - () https://git.kernel.org/stable/c/519547760f16eae7803d2658d9524bc5ba7a20a7 - Patch
References () https://git.kernel.org/stable/c/8111f902b7c95d75fc80c7e577f5045886c6b384 - () https://git.kernel.org/stable/c/8111f902b7c95d75fc80c7e577f5045886c6b384 - Patch
References () https://git.kernel.org/stable/c/cd94cac4069a763ab5206be2c64c9a8beae590ba - () https://git.kernel.org/stable/c/cd94cac4069a763ab5206be2c64c9a8beae590ba - Patch
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*

21 Nov 2024, 09:32

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: Corrija userfaultfd_api para devolver EINVAL como se esperaba. Actualmente, si solicitamos una función que no está configurada en la configuración del kernel, fallamos silenciosamente y devolvemos todas las funciones disponibles. Sin embargo, la página de manual indica que debemos devolver un EINVAL. Necesitamos solucionar este problema ya que podemos terminar con una advertencia del Kernel si un programa solicita la característica UFFD_FEATURE_WP_UNPOPULATED en un kernel con la configuración no configurada con esta característica. [ 200.812896] ADVERTENCIA: CPU: 91 PID: 13634 en mm/memory.c:1660 zap_pte_range+0x43d/0x660 [ 200.820738] Módulos vinculados en: [ 200.869387] CPU: 91 PID: 13634 Comm: userfaultfd Kdump: cargado No contiene ted 6.9. 0-rc5+ #8 [ 200.877477] Nombre del hardware: Dell Inc. PowerEdge R6525/0N7YGH, BIOS 2.7.3 30/03/2022 [ 200.885052] RIP: 0010:zap_pte_range+0x43d/0x660
References () https://git.kernel.org/stable/c/14875fd5f9bcf60ac5518c63bfb676ade44aa7c6 - () https://git.kernel.org/stable/c/14875fd5f9bcf60ac5518c63bfb676ade44aa7c6 -
References () https://git.kernel.org/stable/c/1723f04caacb32cadc4e063725d836a0c4450694 - () https://git.kernel.org/stable/c/1723f04caacb32cadc4e063725d836a0c4450694 -
References () https://git.kernel.org/stable/c/519547760f16eae7803d2658d9524bc5ba7a20a7 - () https://git.kernel.org/stable/c/519547760f16eae7803d2658d9524bc5ba7a20a7 -
References () https://git.kernel.org/stable/c/8111f902b7c95d75fc80c7e577f5045886c6b384 - () https://git.kernel.org/stable/c/8111f902b7c95d75fc80c7e577f5045886c6b384 -
References () https://git.kernel.org/stable/c/cd94cac4069a763ab5206be2c64c9a8beae590ba - () https://git.kernel.org/stable/c/cd94cac4069a763ab5206be2c64c9a8beae590ba -

29 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 15:15

Updated : 2025-10-07 16:32


NVD link : CVE-2024-41027

Mitre link : CVE-2024-41027

CVE.ORG link : CVE-2024-41027


JSON object : View

Products Affected

linux

  • linux_kernel