CVE-2024-57917·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: topology: Keep the cpumask unchanged when printing cpumap During fuzz testing, the following warning was discovered: different return values (15 and 11) from vsnprintf("%*pbl ", ...) test:keyward is WARNING in kvasprintf WARNING: CPU: 55 PID: 1168477 at lib/kasprintf.c:30 kvasprintf+0x121/0x130 Call Trace: kvasprintf+0x121/0x130 kasprintf+0xa6/0xe0 bitmap_print_to_buf+0x89/0x100 core_siblings_list_read+0x7e/0xb0 kernfs_file_read_iter+0x15b/0x270 new_sync_read+0x153/0x260 vfs_read+0x215/0x290 ksys_read+0xb9/0x160 do_syscall_64+0x56/0x100 entry_SYSCALL_64_after_hwframe+0x78/0xe2 The call trace shows that kvasprintf() reported this warning during the printing of core_siblings_list. kvasprintf() has several steps: (1) First, calculate the length of the resulting formatted string. (2) Allocate a buffer based on the returned length. (3) Then, perform the actual string formatting. (4) Check whether the lengths of the formatted strings returned in steps (1) and (2) are consistent. If the core_cpumask is modified between steps (1) and (3), the lengths obtained in these two steps may not match. Indeed our test includes cpu hotplugging, which should modify core_cpumask while printing. To fix this issue, cache the cpumask into a temporary variable before calling cpumap_print_{list, cpumask}_to_buf(), to keep it unchanged during the printing process.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.12.10
- Published
- 2025-01-19
Affected versions
From: 6.7
Until: 6.12.10
Fixed in: 6.12.10
How to fix this CVE
Update your Linux kernel to version 6.12.10 or later to resolve a race condition in CPU topology mask printing that can cause kernel warnings and system instability during CPU hotplug events. Systems running kernel versions 6.7 through 6.12.9 should prioritize this patch to prevent unpredictable behavior when CPUs are dynamically added or removed.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running `uname -r` and compare against 6.12.10
- Step 2: Verify CPU topology files exist at `/sys/devices/system/cpu/cpu*/topology/` which are affected by this vulnerability
- Step 3: Search kernel logs for warnings with `grep -i 'kvasprintf\|core_siblings_list' /var/log/kern.log /var/log/messages` to identify if the race condition has been triggered
- Step 4: After patching, reboot with `sudo reboot` and confirm new kernel version with `uname -r`, then perform CPU hotplug tests to verify stable topology reporting
FAQ
What is CVE-2024-57917?
CVE-2024-57917 is a race condition in the Linux kernel's CPU topology mask printing functionality where the cpumask can change between length calculation and actual formatting, causing kvasprintf() to report length mismatches and kernel warnings during CPU hotplug operations.
Is CVE-2024-57917 being actively exploited?
No, CVE-2024-57917 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, it can cause denial of service through kernel warnings during routine CPU hotplugging.
What versions of Kernel are affected by CVE-2024-57917?
Linux kernel versions 6.7 through 6.12.9 are vulnerable. The fix is included in kernel 6.12.10 and later.
How do I check if my server is vulnerable to CVE-2024-57917?
Run `uname -r` to check your kernel version. If it outputs a version between 6.7 and 6.12.9, your system is vulnerable. Additionally, check logs with `grep 'kvasprintf' /var/log/kern.log` for signs of the race condition being triggered.
Does Defensia detect CVE-2024-57917?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-57917 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/1c7818e2746e747838a3de1687e89eac7b947f08
- https://git.kernel.org/stable/c/360596e7fe319a5db1b5fb34a3952862ae53c924
- https://git.kernel.org/stable/c/b02cf1d27e460ab2b3e1c8c9ce472d562cad2e8d
- https://git.kernel.org/stable/c/ca47e933a900492d89dcf5db18a99c28bd4a742d
- https://git.kernel.org/stable/c/cbd399f78e23ad4492c174fc5e6b3676dba74a52
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-57917. Free for 1 server.
Get started free