CVE-2024-53187 Information
Description
In the Linux kernel the following vulnerability has been resolved:
io_uring: check for overflows in io_pin_pages
WARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144
CPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller 0
Call Trace:
io_pin_pages()’s uaddr parameter came directly from the user and can be garbage. Don’t just add size to it as it can overflow.
Reference
https://git.kernel.org/stable/c/0c0a4eae26ac78379d0c1db053de168a8febc6c9 https://git.kernel.org/stable/c/29eac3eca72d4c2a71122050c37cd7d8f73ac4f3 https://git.kernel.org/stable/c/aaa90844afd499c9142d0199dfda74439314c013
Share on: