U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-27406

Change History

New CVE Received by NIST 5/17/2024 8:15:10 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

lib/Kconfig.debug: TEST_IOV_ITER depends on MMU

Trying to run the iov_iter unit test on a nommu system such as the qemu
kc705-nommu emulation results in a crash.

    KTAP version 1
    # Subtest: iov_iter
    # module: kunit_iov_iter
    1..9
BUG: failure at mm/nommu.c:318/vmap()!
Kernel panic - not syncing: BUG!

The test calls vmap() directly, but vmap() is not supported on nommu
systems, causing the crash.  TEST_IOV_ITER therefore needs to depend on
MMU.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/1eb1e984379e2da04361763f66eec90dd75cf63e [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/9e6e541b97762d5b1143070067f7c68f39a408f8 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/e6316749d603fe9c4c91f6ec3694e06e4de632a3 [No types assigned]