CVE-2024-50278·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: dm cache: fix potential out-of-bounds access on the first resume Out-of-bounds access occurs if the fast device is expanded unexpectedly before the first-time resume of the cache table. This happens because expanding the fast device requires reloading the cache table for cache_create to allocate new in-core data structures that fit the new size, and the check in cache_preresume is not performed during the first resume, leading to the issue. Reproduce steps: 1. prepare component devices: dmsetup create cmeta --table "0 8192 linear /dev/sdc 0" dmsetup create cdata --table "0 65536 linear /dev/sdc 8192" dmsetup create corig --table "0 524288 linear /dev/sdc 262144" dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct 2. load a cache table of 512 cache blocks, and deliberately expand the fast device before resuming the cache, making the in-core data structures inadequate. dmsetup create cache --notable dmsetup reload cache --table "0 524288 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0" dmsetup reload cdata --table "0 131072 linear /dev/sdc 8192" dmsetup resume cdata dmsetup resume cache 3. suspend the cache to write out the in-core dirty bitset and hint array, leading to out-of-bounds access to the dirty bitset at offset 0x40: dmsetup suspend cache KASAN reports: BUG: KASAN: vmalloc-out-of-bounds in is_dirty_callback+0x2b/0x80 Read of size 8 at addr ffffc90000085040 by task dmsetup/90 (...snip...) The buggy address belongs to the virtual mapping at [ffffc90000085000, ffffc90000087000) created by: cache_ctr+0x176a/0x35f0 (...snip...) Memory state around the buggy address: ffffc90000084f00: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ffffc90000084f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 >ffffc90000085000: 00 00 00 00 00 00 00 00 f8 f8 f8 f8 f8 f8 f8 f8 ^ ffffc90000085080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ffffc90000085100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 Fix by checking the size change on the first resume.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.8
- Published
- 2024-11-19
Affected versions
From: 6.7
Until: 6.11.8
Fixed in: 6.11.8
How to fix this CVE
Update your Linux kernel to version 6.11.8 or later to patch a critical out-of-bounds memory access vulnerability in the dm-cache subsystem. This vulnerability is triggered when the fast storage device is expanded before the initial cache table resume, causing memory corruption during cache suspension. Immediate kernel patching is essential to prevent potential system crashes or data corruption.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to check the currently running kernel version; verify it is 6.11.8 or later
- Check if dm-cache is in use by running 'dmsetup ls' and look for any cache targets in the output
- Search system logs for KASAN or memory access errors: 'sudo grep -i "kasan\|out-of-bounds\|vmalloc" /var/log/kern.log /var/log/syslog'
- Verify the fix by confirming the kernel includes commit 036dd6e3d2638103e0092864577ea1d091466b86 using 'git log --oneline | grep 036dd6e'
FAQ
What is CVE-2024-50278?
CVE-2024-50278 is a kernel memory safety bug in the device mapper cache subsystem where expanding a fast device before the initial cache resume leads to out-of-bounds memory access, potentially causing system instability or data corruption.
Is CVE-2024-50278 being actively exploited?
No, CVE-2024-50278 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though it remains a serious local privilege/crash vulnerability.
What versions of Kernel are affected by CVE-2024-50278?
Linux kernel versions 6.7 through 6.11.7 are vulnerable; the fix is included in kernel 6.11.8 and later.
How do I check if my server is vulnerable to CVE-2024-50278?
Run 'uname -r' and compare the version against 6.11.8; if your kernel is between 6.7 and 6.11.7 and dm-cache is loaded (check with 'lsmod | grep dm_cache'), your system is vulnerable.
Does Defensia detect CVE-2024-50278?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-50278 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/036dd6e3d2638103e0092864577ea1d091466b86
- https://git.kernel.org/stable/c/13ed3624c6ef283acefa4cc42cc8ae54fd4391a4
- https://git.kernel.org/stable/c/2222b0929d00e2d13732b799b63be391b5de4492
- https://git.kernel.org/stable/c/483b7261b35a9d369082ab298a6670912243f0be
- https://git.kernel.org/stable/c/c0ade5d98979585d4f5a93e4514c2e9a65afa08d
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50278. Free for 1 server.
Get started free