{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-46847","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-09-11T15:12:18.290Z","datePublished":"2024-09-27T12:39:39.550Z","dateUpdated":"2026-08-05T11:38:58.890Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:38:58.890Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: vmalloc: ensure vmap_block is initialised before adding to queue\n\nCommit 8c61291fd850 (\"mm: fix incorrect vbq reference in\npurge_fragmented_block\") extended the 'vmap_block' structure to contain a\n'cpu' field which is set at allocation time to the id of the initialising\nCPU.\n\nWhen a new 'vmap_block' is being instantiated by new_vmap_block(), the\npartially initialised structure is added to the local 'vmap_block_queue'\nxarray before the 'cpu' field has been initialised.  If another CPU is\nconcurrently walking the xarray (e.g.  via vm_unmap_aliases()), then it\nmay perform an out-of-bounds access to the remote queue thanks to an\nuninitialised index.\n\nThis has been observed as UBSAN errors in Android:\n\n | Internal error: UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n |\n | Call trace:\n |  purge_fragmented_block+0x204/0x21c\n |  _vm_unmap_aliases+0x170/0x378\n |  vm_unmap_aliases+0x1c/0x28\n |  change_memory_common+0x1dc/0x26c\n |  set_memory_ro+0x18/0x24\n |  module_enable_ro+0x98/0x238\n |  do_init_module+0x1b0/0x310\n\nMove the initialisation of 'vb->cpu' in new_vmap_block() ahead of the\naddition to the xarray."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is core mm/vmalloc block allocation, reached through ordinary local syscall activity (read/write of compressed f2fs/erofs files, dma-buf/V4L2 buffer mapping, vmalloc/vfree churn). No network protocol handler reaches it.\nAC:L - The attacker controls both sides of the race — one thread drives vm_map_ram()/new_vmap_block() while another drives vm_unmap_aliases() on a different CPU — and the window is fully preemptible (no locks held, RCU section already exited), so it can be widened and retried indefinitely; it was observed triggering spontaneously in production Android without any attacker.\nPR:L - Every path to both sides of the race (f2fs/erofs compressed file I/O, udmabuf, videobuf2, vfree of VM_FLUSH_RESET_PERMS areas) is available to a plain unprivileged local user with no capability check anywhere along the trace.\nUI:N - The attacker's own threads perform all required operations; no victim action, mount, or file open by another user is needed.\nS:U - The uninitialized read, the out-of-bounds array access and the resulting crash all occur within the kernel's own security authority, with no crossing of a VM, IOMMU or sandbox boundary.\nC:H - __per_cpu_offset[vb->cpu] is an out-of-bounds read with an unbounded 32-bit index (up to ~32 GiB past the array) that is attacker-groomable, since struct vmap_block lands in kmalloc-256 and the uninitialized cpu field can be pre-seeded via heap spray — an attacker-directed read of arbitrary kernel memory, not a bounded few-byte overread.\nI:H - The out-of-bounds load produces a fully wild vmap_block_queue pointer built from attacker-influenceable data, which is subsequently used as a lock/list target inside purge_fragmented_block(), giving corruption of memory at an attacker-steered offset.\nA:H - The bug is a confirmed kernel panic — UBSAN array-index trap on Android, or an unhandled kernel page fault on the wild __per_cpu_offset[] load — and the oops happens while holding vmap_purge_lock and vb->lock inside an RCU read section, permanently deadlocking the vmap layer for all subsequent vmalloc/vfree."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/vmalloc.c"],"versions":[{"version":"88e0ad40d08a73a74c597e69f4cd2d1fba3838b5","lessThan":"1b2770e27d6d952f491bb362b657e5b2713c3efd","status":"affected","versionType":"git"},{"version":"8c61291fd8500e3b35c7ec0c781b273d8cc96cde","lessThan":"6cf74e0e5e3ab5d5c9defb4c73dad54d52224671","status":"affected","versionType":"git"},{"version":"8c61291fd8500e3b35c7ec0c781b273d8cc96cde","lessThan":"3e3de7947c751509027d26b679ecd243bc9db255","status":"affected","versionType":"git"},{"version":"9983b81579be3403f5cc44b11f66c6c8bea6547f","status":"affected","versionType":"git"},{"version":"6.6.37","lessThan":"6.6.51","status":"affected","versionType":"semver"},{"version":"6.9.8","lessThan":"6.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/vmalloc.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.6.51","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.10.10","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.37","versionEndExcluding":"6.6.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.10.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1b2770e27d6d952f491bb362b657e5b2713c3efd"},{"url":"https://git.kernel.org/stable/c/6cf74e0e5e3ab5d5c9defb4c73dad54d52224671"},{"url":"https://git.kernel.org/stable/c/3e3de7947c751509027d26b679ecd243bc9db255"}],"title":"mm: vmalloc: ensure vmap_block is initialised before adding to queue","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-29T13:58:55.254929Z","id":"CVE-2024-46847","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-29T13:58:59.658Z"}}]}}