In the Linux kernel, the following vulnerability has been resolved:
filelock: Fix fcntl/close race recovery compat path
When I wrote commit 3cad1bc01041 ("filelock: Remove locks reliably when fcntl/close race is detected"), I missed that there are two copies of the code I was patching: The normal version, and the version for 64-bit offsets on 32-bit kernels. Thanks to Greg KH for stumbling over this while doing the stable backport...
Apply exactly the same fix to the compat path for 32-bit kernels.
[ { "deprecated": false, "id": "CVE-2024-41020-0c29430f", "signature_type": "Function", "digest": { "length": 1104.0, "function_hash": "233111745835851559243575604612056071016" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4d0775c6e2f1340ca0725f0337de149aaa989ca", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-24ad2996", "signature_type": "Function", "digest": { "length": 1144.0, "function_hash": "90319011554847941623372988158756837840" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ed898f9ca3fa32c56c858b463ceb9d9936cc69c4", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-4430b156", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "6907224549804133218570307859804668329", "50966820559474883161142185645909461222", "312927218998847840204268758412114082173", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c43ad4ab41602201d34c66ac62130fe339d686f", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-4b11a4c6", "signature_type": "Function", "digest": { "length": 1205.0, "function_hash": "49320412708274359366364561149549804047" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c43ad4ab41602201d34c66ac62130fe339d686f", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-5103c8c4", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "84071386942499629225685867772422222416", "272441913478677934027037319452771370255", "42249650959075666483246258890105686038", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4d0775c6e2f1340ca0725f0337de149aaa989ca", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-5178e635", "signature_type": "Function", "digest": { "length": 1144.0, "function_hash": "90319011554847941623372988158756837840" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f8138f2ad2f745b9a1c696a05b749eabe44337ea", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-6057d619", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "84071386942499629225685867772422222416", "272441913478677934027037319452771370255", "42249650959075666483246258890105686038", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@73ae349534ebc377328e7d21891e589626c6e82c", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-8cd07363", "signature_type": "Line", "digest": { "line_hashes": [ "80829472260784036770702771310495067773", "282020585415272864250580627075191982533", "190370552893506949617508394921673370902", "332593379845088875226709087083876724746", "301406762659857069039567976171353475132", "166022863381839267301357058146526725449", "218709868825923716027467339014331217600", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ed898f9ca3fa32c56c858b463ceb9d9936cc69c4", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-a78de023", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "6907224549804133218570307859804668329", "50966820559474883161142185645909461222", "312927218998847840204268758412114082173", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a561145f3ae973ebf3e0aee41624e92a6c5cb38d", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-afb0efb6", "signature_type": "Line", "digest": { "line_hashes": [ "80829472260784036770702771310495067773", "282020585415272864250580627075191982533", "190370552893506949617508394921673370902", "332593379845088875226709087083876724746", "301406762659857069039567976171353475132", "166022863381839267301357058146526725449", "218709868825923716027467339014331217600", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5b0af8e4c70e4b884bb94ff5f0cd49ecf1273c02", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-b09f4482", "signature_type": "Function", "digest": { "length": 1104.0, "function_hash": "233111745835851559243575604612056071016" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@73ae349534ebc377328e7d21891e589626c6e82c", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-b1b14203", "signature_type": "Function", "digest": { "length": 1144.0, "function_hash": "90319011554847941623372988158756837840" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5b0af8e4c70e4b884bb94ff5f0cd49ecf1273c02", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-ce9835c1", "signature_type": "Line", "digest": { "line_hashes": [ "80829472260784036770702771310495067773", "282020585415272864250580627075191982533", "190370552893506949617508394921673370902", "332593379845088875226709087083876724746", "301406762659857069039567976171353475132", "166022863381839267301357058146526725449", "218709868825923716027467339014331217600", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f8138f2ad2f745b9a1c696a05b749eabe44337ea", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-e0420976", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "84071386942499629225685867772422222416", "272441913478677934027037319452771370255", "42249650959075666483246258890105686038", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@53e21cfa68a7d12de378b7116c75571f73e0dfa2", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-e9a5d7bc", "signature_type": "Function", "digest": { "length": 1104.0, "function_hash": "233111745835851559243575604612056071016" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@53e21cfa68a7d12de378b7116c75571f73e0dfa2", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-edc75095", "signature_type": "Line", "digest": { "line_hashes": [ "220002780221748930299965198091503039703", "234149167103988640631344224576152972524", "84071386942499629225685867772422222416", "272441913478677934027037319452771370255", "42249650959075666483246258890105686038", "23063494954710860161591770370615255890", "213213471308360415974963396683832274027", "117838873956421721676474737888652432630", "138416546213626093740182540492628315375" ], "threshold": 0.9 }, "target": { "file": "fs/locks.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@911cc83e56a2de5a40758766c6a70d6998248860", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-f675665a", "signature_type": "Function", "digest": { "length": 1230.0, "function_hash": "220443666646984974859908894085060811634" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@911cc83e56a2de5a40758766c6a70d6998248860", "signature_version": "v1" }, { "deprecated": false, "id": "CVE-2024-41020-f8d06151", "signature_type": "Function", "digest": { "length": 1205.0, "function_hash": "49320412708274359366364561149549804047" }, "target": { "file": "fs/locks.c", "function": "fcntl_setlk64" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a561145f3ae973ebf3e0aee41624e92a6c5cb38d", "signature_version": "v1" } ]