CVE-2024-41021
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC on s390.
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC on s390. Therefore we do not expect to see VM_FAULT_HWPOISON in do_exception(). However, since commit af19487f00f3 ("mm: make PTE_MARKER_SWAPIN_ERROR more general"), it is possible to see VM_FAULT_HWPOISON in combination with PTE_MARKER_POISONED, even on architectures that do not support HWPOISON otherwise. In this case, we will end up on the BUG() in do_exception(). Fix this by treating VM_FAULT_HWPOISON the same as VM_FAULT_SIGBUS, similar to x86 when MEMORY_FAILURE is not configured. Also print unexpected fault flags, for easier debugging. Note that VM_FAULT_HWPOISON_LARGE is not expected, because s390 cannot support swap entries on other levels than PTE level.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/73a9260b7366d2906ec011e100319359fe2277d0Patch
- https://git.kernel.org/stable/c/9e13767ccefdc4f8aa92514b592b60f6b54882ffPatch
- https://git.kernel.org/stable/c/a3aefb871222a9880602d1a44a558177b4143e3bPatch
- https://git.kernel.org/stable/c/df39038cd89525d465c2c8827eb64116873f141aPatch
- https://git.kernel.org/stable/c/9e13767ccefdc4f8aa92514b592b60f6b54882ffPatch
- https://git.kernel.org/stable/c/a3aefb871222a9880602d1a44a558177b4143e3bPatch
- https://git.kernel.org/stable/c/df39038cd89525d465c2c8827eb64116873f141aPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.