{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-45022",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-08-21T05:34:56.684Z",
        "datePublished": "2024-09-11T15:13:55.837Z",
        "dateUpdated": "2026-08-05T11:37:47.009Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:37:47.009Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0\n\nThe __vmap_pages_range_noflush() assumes its argument pages** contains\npages with the same page shift.  However, since commit e9c3cda4d86e (\"mm,\nvmalloc: fix high order __GFP_NOFAIL allocations\"), if gfp_flags includes\n__GFP_NOFAIL with high order in vm_area_alloc_pages() and page allocation\nfailed for high order, the pages** may contain two different page shifts\n(high order and order-0).  This could lead __vmap_pages_range_noflush() to\nperform incorrect mappings, potentially resulting in memory corruption.\n\nUsers might encounter this as follows (vmap_allow_huge = true, 2M is for\nPMD_SIZE):\n\nkvmalloc(2M, __GFP_NOFAIL|GFP_X)\n    __vmalloc_node_range_noprof(vm_flags=VM_ALLOW_HUGE_VMAP)\n        vm_area_alloc_pages(order=9) ---> order-9 allocation failed and fallback to order-0\n            vmap_pages_range()\n                vmap_pages_range_noflush()\n                    __vmap_pages_range_noflush(page_shift = 21) ----> wrong mapping happens\n\nWe can remove the fallback code because if a high-order allocation fails,\n__vmalloc_node_range_noprof() will retry with order-0.  Therefore, it is\nunnecessary to fallback to order-0 here.  Therefore, fix this by removing\nthe fallback code."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The flaw is in the core vmalloc allocator and is reached through ordinary local allocation activity (syscalls, filesystem and driver paths that use kvmalloc/vmalloc_huge with __GFP_NOFAIL); no remote protocol handler drives a ≥PMD_SIZE __GFP_NOFAIL vmalloc, so it requires local access.\nAC:L - The only precondition is that the order-9 allocation fails, which an unprivileged process can reliably induce by creating memory pressure and fragmentation; once any high-order attempt fails, the order-0 fallback is taken and the wrong-shift mapping is produced deterministically with no race to win.\nPR:L - A basic unprivileged local user can both drive memory fragmentation and trigger the large __GFP_NOFAIL kvmalloc paths through normal filesystem/driver operations; no capability or namespace privilege is checked anywhere along the path from kvmalloc() into vm_area_alloc_pages().\nUI:N - Triggering only requires the attacker's own allocation and memory-pressure activity; no victim action, mount, or file open by another user is needed.\nS:U - The mis-mapping corrupts kernel memory within the same kernel security authority; there is no hypervisor, IOMMU, or sandbox boundary crossed.\nC:H - The returned buffer aliases up to 2 MiB of physical memory per PMD that was never allocated to it, so reading it discloses arbitrary adjacent kernel and user data (slab objects, page tables, page cache, other tasks' pages).\nI:H - The same alias window is mapped PAGE_KERNEL read-write, so writes through the vmalloc pointer corrupt unrelated physical frames — an arbitrary-write primitive over neighbouring memory that can be steered at creds, page tables, or function pointers for privilege escalation.\nA:H - Overwriting foreign physical frames (page tables, slab metadata) or mapping non-RAM pfns readily produces oopses, machine checks, and kernel panics."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "mm/vmalloc.c"
                    ],
                    "versions": [
                        {
                            "version": "fe5c2bdcb14c8612eb5e7a09159801c7219e9ac4",
                            "lessThan": "fd1ffbb50ef4da5e1378a46616b6d7407dc795da",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e9c3cda4d86e56bf7fe403729f38c4f0f65d3860",
                            "lessThan": "de7bad86345c43cd040ed43e20d9fad78a3ee59f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e9c3cda4d86e56bf7fe403729f38c4f0f65d3860",
                            "lessThan": "c91618816f4d21fc574d7577a37722adcd4075b2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e9c3cda4d86e56bf7fe403729f38c4f0f65d3860",
                            "lessThan": "61ebe5a747da649057c37be1c37eb934b4af79ca",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.1.95",
                            "lessThan": "6.1.107",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "mm/vmalloc.c"
                    ],
                    "versions": [
                        {
                            "version": "6.3",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.3",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.107",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.48",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10.7",
                            "lessThanOrEqual": "6.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.95",
                                    "versionEndExcluding": "6.1.107"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.6.48"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.10.7"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.11"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/fd1ffbb50ef4da5e1378a46616b6d7407dc795da"
                },
                {
                    "url": "https://git.kernel.org/stable/c/de7bad86345c43cd040ed43e20d9fad78a3ee59f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c91618816f4d21fc574d7577a37722adcd4075b2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/61ebe5a747da649057c37be1c37eb934b4af79ca"
                }
            ],
            "title": "mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-09-29T15:47:43.491220Z",
                                "id": "CVE-2024-45022",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-29T15:47:57.703Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T22:15:32.309Z"
                }
            }
        ]
    }
}