U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-42250

Change History

New CVE Received by NIST 8/07/2024 12:15:47 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

cachefiles: add missing lock protection when polling

Add missing lock protection in poll routine when iterating xarray,
otherwise:

Even with RCU read lock held, only the slot of the radix tree is
ensured to be pinned there, while the data structure (e.g. struct
cachefiles_req) stored in the slot has no such guarantee.  The poll
routine will iterate the radix tree and dereference cachefiles_req
accordingly.  Thus RCU read lock is not adequate in this case and
spinlock is needed here.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/6bb6bd3dd6f382dfd36220d4b210a0c77c066651 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/8eadcab7f3dd809edbe5ae20533ff843dfea3a07 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/97cfd5e20ddc2e33e16ce369626ce76c9a475fd7 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/cf5bb09e742a9cf6349127e868329a8f69b7a014 [No types assigned]