SB2024061327 - Improper locking in Linux kernel io_uring
Published: June 13, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2024-35880)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the __io_remove_buffers() and io_unregister_pbuf_ring() functions in io_uring/kbuf.c, within the io_uring_validate_mmap_request() function in io_uring/io_uring.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/65938e81df2197203bda4b9a0c477e7987218d66
- https://git.kernel.org/stable/c/5fd8e2359498043e0b5329a05f02d10a9eb91eb9
- https://git.kernel.org/stable/c/561e4f9451d65fc2f7eef564e0064373e3019793
- https://www.zerodayinitiative.com/advisories/ZDI-24-1018/
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.26
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.5