#VU92022 Improper locking in Linux kernel - CVE-2024-35880
Published: June 13, 2024 / Updated: May 13, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the __io_remove_buffers() and io_unregister_pbuf_ring() functions in io_uring/kbuf.c, within the io_uring_validate_mmap_request() function in io_uring/io_uring.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/65938e81df2197203bda4b9a0c477e7987218d66
- https://git.kernel.org/stable/c/5fd8e2359498043e0b5329a05f02d10a9eb91eb9
- https://git.kernel.org/stable/c/561e4f9451d65fc2f7eef564e0064373e3019793
- https://www.zerodayinitiative.com/advisories/ZDI-24-1018/
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.26
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.5