CVE-2024-35974

Source
https://cve.org/CVERecord?id=CVE-2024-35974
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35974.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35974
Downstream
Related
Published
2024-05-20T09:42:01Z
Modified
2026-05-18T05:56:05Z
Summary
block: fix q->blkg_list corruption during disk rebind
Details

In the Linux kernel, the following vulnerability has been resolved:

block: fix q->blkg_list corruption during disk rebind

Multiple gendisk instances can allocated/added for single request queue in case of disk rebind. blkg may still stay in q->blkg_list when calling blkcg_init_disk() for rebind, then q->blkg_list becomes corrupted.

Fix the list corruption issue by:

  • add blkg_init_queue() to initialize q->blkg_list & q->blkcg_mutex only
  • move calling blkg_init_queue() into blk_alloc_queue()

The list corruption should be started since commit f1c006f1c685 ("blk-cgroup: synchronize pd_free_fn() from blkg_free_workfn() and blkcg_deactivate_policy()") which delays removing blkg from q->blkg_list into blkg_free_workfn().

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35974.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
81c1188905f88b77743d1fdeeedfc8cb7b67787d
Fixed
b5dae1cd0d8368b4338430ff93403df67f0b8bcc
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a
Fixed
083b58373463a6e5ee60ecb135269348f68ad7df
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1059699f87eb0b3aa9d574b91a572d534897134a
Fixed
740ffad95ca8033bd6e080ed337655b13b4d38ac
Fixed
858c489d81d659af17a4d11cfaad2afb42e47a76
Fixed
8b8ace080319a866f5dfe9da8e665ae51d971c54

Affected versions

v6.*
v6.1.16
v6.2.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35974.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.17
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.4
Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.28
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35974.json"