CVE-2024-40900·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: cachefiles: remove requests from xarray during flushing requests Even with CACHEFILES_DEAD set, we can still read the requests, so in the following concurrency the request may be used after it has been freed: mount | daemon_thread1 | daemon_thread2 ------------------------------------------------------------ cachefiles_ondemand_init_object cachefiles_ondemand_send_req REQ_A = kzalloc(sizeof(*req) + data_len) wait_for_completion(&REQ_A->done) cachefiles_daemon_read cachefiles_ondemand_daemon_read // close dev fd cachefiles_flush_reqs complete(&REQ_A->done) kfree(REQ_A) xa_lock(&cache->reqs); cachefiles_ondemand_select_req req->msg.opcode != CACHEFILES_OP_READ // req use-after-free !!! xa_unlock(&cache->reqs); xa_destroy(&cache->reqs) Hence remove requests from cache->reqs when flushing them to avoid accessing freed requests.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.9.6
- Published
- 2024-07-12
Affected versions
From: 6.7
Until: 6.9.6
Fixed in: 6.9.6
How to fix this CVE
Update your Linux kernel to version 6.9.6 or later to resolve a use-after-free vulnerability in the cachefiles subsystem. This flaw can allow local privilege escalation through concurrent access to freed kernel memory during cache operations. Prioritize patching systems running kernel versions 6.7 through 6.9.5.
sudo dnf check-update kernel && sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r
- Verify if cachefiles is loaded: lsmod | grep cachefiles
- Confirm vulnerable version range (6.7 to 6.9.5): if your kernel version falls between these, your system is vulnerable
- After patching, reboot and verify the new version: uname -r (should be 6.9.6 or higher)
FAQ
What is CVE-2024-40900?
CVE-2024-40900 is a use-after-free vulnerability in the Linux kernel's cachefiles subsystem. A race condition between cache flushing and request processing allows freed memory to be accessed, potentially leading to privilege escalation from a local user.
Is CVE-2024-40900 being actively exploited?
No, CVE-2024-40900 is not currently listed as actively exploited in the CISA KEV catalog, and no public exploits are known.
What versions of Kernel are affected by CVE-2024-40900?
Kernel versions 6.7 through 6.9.5 are affected. Version 6.9.6 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-40900?
Run 'uname -r' and compare your kernel version against the vulnerable range (6.7–6.9.5). If your version falls within this range, update immediately.
Does Defensia detect CVE-2024-40900?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-40900 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0fc75c5940fa634d84e64c93bfc388e1274ed013
- https://git.kernel.org/stable/c/37e19cf86a520d65de1de9cb330415c332a40d19
- https://git.kernel.org/stable/c/50d0e55356ba5b84ffb51c42704126124257e598
- https://git.kernel.org/stable/c/9f13aacdd4ee9a7644b2a3c96d67113cd083c9c7
- https://git.kernel.org/stable/c/0fc75c5940fa634d84e64c93bfc388e1274ed013
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-40900. Free for 1 server.
Get started free