{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-57875","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-01-11T14:45:42.023Z","datePublished":"2025-01-11T14:49:01.655Z","dateUpdated":"2026-08-05T11:46:43.350Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:46:43.350Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: RCU protect disk->conv_zones_bitmap\n\nEnsure that a disk revalidation changing the conventional zones bitmap\nof a disk does not cause invalid memory references when using the\ndisk_zone_is_conv() helper by RCU protecting the disk->conv_zones_bitmap\npointer.\n\ndisk_zone_is_conv() is modified to operate under the RCU read lock and\nthe function disk_set_conv_zones_bitmap() is added to update a disk\nconv_zones_bitmap pointer using rcu_replace_pointer() with the disk\nzone_wplugs_lock spinlock held.\n\ndisk_free_zone_resources() is modified to call\ndisk_update_zone_resources() with a NULL bitmap pointer to free the disk\nconv_zones_bitmap. disk_set_conv_zones_bitmap() is also used in\ndisk_update_zone_resources() to set the new (revalidated) bitmap and\nfree the old one."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable helper is reached only through the local block I/O submission path (`submit_bio`/`blk_mq_submit_bio` → `blk_zone_plug_bio`) and zone-management ioctls (`BLKRESETZONE`/`BLKFINISHZONE`) against a zoned block device node or a filesystem mounted on it. There is no network protocol handler in the path; the racing revalidation is a local block-layer/driver operation.\nAC:L - The attacker fully controls the reader side and can drive `disk_zone_is_conv()` continuously and indefinitely with a cheap write/zone-reset loop, so the race can be retried without limit at no cost until a revalidation (admin rescan, `BLKRRPART`, DM table reload, or a device-driven SCSI capacity-change unit attention / NVMe namespace-changed AEN, all of which recur in normal operation) lands in the window. No specific memory layout or victim state that the attacker cannot influence is required.\nPR:L - An ordinary unprivileged local user only needs write access to the zoned block device or to a filesystem on it (common for containers given a ZNS namespace, storage hosts with SMR disks, and Android/embedded systems running f2fs on zoned storage) to keep the vulnerable read path hot. No capability check guards `blk_zone_plug_bio()` on the submission path.\nUI:N - Triggering requires only the attacker's own I/O against the zoned device concurrently with a revalidation event; no victim has to open a file, mount a filesystem, or take any other action.\nS:U - The freed bitmap and the corrupted decision logic are both kernel block-layer state, so the impact stays within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - `test_bit()` on the freed bitmap reads memory that may already have been reallocated to another kernel object, and the resulting bit value is observable to the attacker through the differing I/O behavior (zone append accepted vs. `-EIO`), yielding a use-after-free read oracle over recycled kernel heap contents.\nI:H - A stale/freed bitmap can make a sequential-write-required zone be classified as conventional, causing writes to bypass zone write plugging entirely and be issued out of order to the device — corrupting on-disk data on the zoned device — and the use-after-free read is the kind of memory-safety defect that is treated as exploitable for further corruption.\nA:H - Dereferencing the freed bitmap can oops the kernel (kvmalloc/vmalloc-backed bitmaps for large zone counts become unmapped on free, and KASAN/DEBUG_PAGEALLOC builds fault immediately), and even without a fault the misclassification produces write-ordering failures that force I/O errors and filesystem shutdown on the zoned device."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk-zoned.c","include/linux/blkdev.h"],"versions":[{"version":"dd291d77cc90eb6a86e9860ba8e6e38eebd57d12","lessThan":"493326c4f10cc71a42c27fdc97ce112182ee4cbc","status":"affected","versionType":"git"},{"version":"dd291d77cc90eb6a86e9860ba8e6e38eebd57d12","lessThan":"d7cb6d7414ea1b33536fa6d11805cb8dceec1f97","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk-zoned.c","include/linux/blkdev.h"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.12.5","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.13","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.12.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.13"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/493326c4f10cc71a42c27fdc97ce112182ee4cbc"},{"url":"https://git.kernel.org/stable/c/d7cb6d7414ea1b33536fa6d11805cb8dceec1f97"}],"title":"block: RCU protect disk->conv_zones_bitmap","x_generator":{"engine":"bippy-1.2.0"}}}}