CVE-2024-44965

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-44965
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44965.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-44965
Downstream
Related
Published
2024-09-04T18:36:02.762Z
Modified
2025-11-27T02:32:12.650913Z
Summary
x86/mm: Fix pti_clone_pgtable() alignment assumption
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/mm: Fix pticlonepgtable() alignment assumption

Guenter reported dodgy crashes on an i386-nosmp build using GCC-11 that had the form of endless traps until entry stack exhaust and then

DF from the stack guard.

It turned out that pticlonepgtable() had alignment assumptions on the start address, notably it hard assumes start is PMD aligned. This is true on x86_64, but very much not true on i386.

These assumptions can cause the end condition to malfunction, leading to a 'short' clone. Guess what happens when the user mapping has a short copy of the entry text?

Use the correct increment form for addr to avoid alignment assumptions.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2024/44xxx/CVE-2024-44965.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
18da1b27ce16a14a9b636af9232acb4fb24f4c9e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
25a727233a40a9b33370eec9f0cad67d8fd312f8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
d00c9b4bbc442d99e1dafbdfdab848bc1ead73f6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
4d143ae782009b43b4f366402e5c37f59d4e4346
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
5c580c1050bcbc15c3e78090859d798dcf8c9763
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
ca07aab70dd3b5e7fddb62d7a6ecd7a7d6d0b2ed
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
df3eecb5496f87263d171b254ca6e2758ab3c35c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16a3fe634f6a568c6234b8747e5d50487fed3526
Fixed
41e71dbb0e0a0fe214545fe64af031303a08524c

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
4.19.320
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.282
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.224
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.165
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.105
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.46
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.5