In the Linux kernel, the following vulnerability has been resolved:
fs/proc/task_mmu: fix loss of young/dirty bits during pagemap scan
make_uffd_wp_pte() was previously doing:
pte = ptep_get(ptep);
ptep_modify_prot_start(ptep);
pte = pte_mkuffd_wp(pte);
ptep_modify_prot_commit(ptep, pte);
But if another thread accessed or dirtied the pte between the first 2
calls, this could lead to loss of that information. Since
ptep_modify_prot_start() gets and clears atomically, the following is the
correct pattern and prevents any possible race. Any access after the
first call would see an invalid pte and cause a fault:
pte = ptep_modify_prot_start(ptep);
pte = pte_mkuffd_wp(pte);
ptep_modify_prot_commit(ptep, pte);
References
Configurations
Configuration 1 (hide)
|
History
01 Oct 2025, 14:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/74b3d66f91d9f539f99faad74d796fa9a389a015 - Patch | |
| References | () https://git.kernel.org/stable/c/c70dce4982ce1718bf978a35f8e26160b82081f4 - Patch | |
| CPE | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
| CWE | NVD-CWE-noinfo | |
| First Time |
Linux linux Kernel
Linux |
21 Nov 2024, 09:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/74b3d66f91d9f539f99faad74d796fa9a389a015 - | |
| References | () https://git.kernel.org/stable/c/c70dce4982ce1718bf978a35f8e26160b82081f4 - | |
| Summary |
|
30 May 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-05-30 16:15
Updated : 2025-10-01 14:01
NVD link : CVE-2024-36943
Mitre link : CVE-2024-36943
CVE.ORG link : CVE-2024-36943
JSON object : View
Products Affected
linux
- linux_kernel
CWE
