{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-47668","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-09-30T16:00:12.936Z","datePublished":"2024-10-09T14:14:00.189Z","dateUpdated":"2026-08-05T11:39:17.526Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:39:17.526Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()\n\nIf we need to increase the tree depth, allocate a new node, and then\nrace with another thread that increased the tree depth before us, we'll\nstill have a preallocated node that might be used later.\n\nIf we then use that node for a new non-root node, it'll still have a\npointer to the old root instead of being zeroed - fix this by zeroing it\nin the cmpxchg failure path."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The only genradix users with lock-free concurrent `__genradix_ptr_alloc()` on a shared tree are bcachefs (`bch2_quota_acct()` on the write/inode-create path, `__ec_stripe_mem_alloc()` in erasure coding), reached via ordinary local filesystem syscalls; SCTP's per-association trees are serialized under the socket lock and `fs/proc/base.c` uses a stack-local tree, so no remote path exists.\nAC:L - The attacker drives both sides of the race with their own threads — concurrent writes/creates from multiple tasks each call `genradix_ptr_alloc()` outside `q->lock`, and the depth-increase point is deterministic (first access beyond current tree capacity), so it can be targeted and retried at will.\nPR:L - No capability is required: any unprivileged local user with write access on a mounted bcachefs volume triggers `bch2_quota_acct()`/stripe allocation through plain `write()`, `creat()`, and `chown()`, and reads the resulting corrupted counter back via `quotactl(Q_GETQUOTA)` for their own id.\nUI:N - The attacker's own concurrent threads perform every step; no victim action is needed once the filesystem is mounted as part of normal system operation.\nS:U - The corruption is confined to kernel heap objects managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - A dirty node used as a leaf leaves a live kernel heap pointer where zeros are guaranteed, and for bcachefs quotas that value is returned to unprivileged userspace as `d_space` via `quotactl(Q_GETQUOTA)`; the interior-node aliasing additionally exposes unrelated tree contents and gives a read primitive over corrupted pointers.\nI:H - When the dirty node is installed at an interior level, two distinct indices alias onto the same node, so attacker-controlled u64 counter data overwrites live `children[]` pointers of a node still in the tree — a controlled write over kernel pointers that are later dereferenced and freed.\nA:H - The aliased node is reachable twice from `genradix_free_recurse()`, producing a double `kfree()` of a 512-byte slab object plus `kfree()` of fabricated pointer values, and corrupted quota counters directly trip `BUG_ON()` in `__bch2_quota_transfer()`/`__bch2_quota_reservation_put()` — all kernel panics."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["lib/generic-radix-tree.c"],"versions":[{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"0f27f4f445390cb7f73d4209cb2bf32834dc53da","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"99418ec776a39609f50934720419e0b464ca2283","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"ebeff038744c498a036e7a92eb8e433ae0a386d7","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"d942e855324a60107025c116245095632476613e","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"0f078f8ca93b28a34e20bd050f12cd4efeee7c0f","status":"affected","versionType":"git"},{"version":"ba20ba2e3743bac786dff777954c11930256075e","lessThan":"b2f11c6f3e1fc60742673b8675c95b78447f3dae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["lib/generic-radix-tree.c"],"versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","status":"unaffected","versionType":"semver"},{"version":"5.4.284","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.226","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.167","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.110","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.51","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.10.10","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"5.4.284"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"5.10.226"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"5.15.167"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.1.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.6.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.10.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0f27f4f445390cb7f73d4209cb2bf32834dc53da"},{"url":"https://git.kernel.org/stable/c/99418ec776a39609f50934720419e0b464ca2283"},{"url":"https://git.kernel.org/stable/c/ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169"},{"url":"https://git.kernel.org/stable/c/ebeff038744c498a036e7a92eb8e433ae0a386d7"},{"url":"https://git.kernel.org/stable/c/d942e855324a60107025c116245095632476613e"},{"url":"https://git.kernel.org/stable/c/0f078f8ca93b28a34e20bd050f12cd4efeee7c0f"},{"url":"https://git.kernel.org/stable/c/b2f11c6f3e1fc60742673b8675c95b78447f3dae"}],"title":"lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-10-10T13:21:11.227741Z","id":"CVE-2024-47668","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-10T13:21:24.795Z"}},{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T22:20:33.256Z"}}]}}