{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-57875",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-01-11T14:45:42.023Z",
        "datePublished": "2025-01-11T14:49:01.655Z",
        "dateUpdated": "2026-08-05T11:46:43.350Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:46:43.350Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: RCU protect disk->conv_zones_bitmap\n\nEnsure that a disk revalidation changing the conventional zones bitmap\nof a disk does not cause invalid memory references when using the\ndisk_zone_is_conv() helper by RCU protecting the disk->conv_zones_bitmap\npointer.\n\ndisk_zone_is_conv() is modified to operate under the RCU read lock and\nthe function disk_set_conv_zones_bitmap() is added to update a disk\nconv_zones_bitmap pointer using rcu_replace_pointer() with the disk\nzone_wplugs_lock spinlock held.\n\ndisk_free_zone_resources() is modified to call\ndisk_update_zone_resources() with a NULL bitmap pointer to free the disk\nconv_zones_bitmap. disk_set_conv_zones_bitmap() is also used in\ndisk_update_zone_resources() to set the new (revalidated) bitmap and\nfree the old one."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable helper is reached only through the local block I/O submission path (`submit_bio`/`blk_mq_submit_bio` → `blk_zone_plug_bio`) and zone-management ioctls (`BLKRESETZONE`/`BLKFINISHZONE`) against a zoned block device node or a filesystem mounted on it. There is no network protocol handler in the path; the racing revalidation is a local block-layer/driver operation.\nAC:L - The attacker fully controls the reader side and can drive `disk_zone_is_conv()` continuously and indefinitely with a cheap write/zone-reset loop, so the race can be retried without limit at no cost until a revalidation (admin rescan, `BLKRRPART`, DM table reload, or a device-driven SCSI capacity-change unit attention / NVMe namespace-changed AEN, all of which recur in normal operation) lands in the window. No specific memory layout or victim state that the attacker cannot influence is required.\nPR:L - An ordinary unprivileged local user only needs write access to the zoned block device or to a filesystem on it (common for containers given a ZNS namespace, storage hosts with SMR disks, and Android/embedded systems running f2fs on zoned storage) to keep the vulnerable read path hot. No capability check guards `blk_zone_plug_bio()` on the submission path.\nUI:N - Triggering requires only the attacker's own I/O against the zoned device concurrently with a revalidation event; no victim has to open a file, mount a filesystem, or take any other action.\nS:U - The freed bitmap and the corrupted decision logic are both kernel block-layer state, so the impact stays within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - `test_bit()` on the freed bitmap reads memory that may already have been reallocated to another kernel object, and the resulting bit value is observable to the attacker through the differing I/O behavior (zone append accepted vs. `-EIO`), yielding a use-after-free read oracle over recycled kernel heap contents.\nI:H - A stale/freed bitmap can make a sequential-write-required zone be classified as conventional, causing writes to bypass zone write plugging entirely and be issued out of order to the device — corrupting on-disk data on the zoned device — and the use-after-free read is the kind of memory-safety defect that is treated as exploitable for further corruption.\nA:H - Dereferencing the freed bitmap can oops the kernel (kvmalloc/vmalloc-backed bitmaps for large zone counts become unmapped on free, and KASAN/DEBUG_PAGEALLOC builds fault immediately), and even without a fault the misclassification produces write-ordering failures that force I/O errors and filesystem shutdown on the zoned device."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "block/blk-zoned.c",
                        "include/linux/blkdev.h"
                    ],
                    "versions": [
                        {
                            "version": "dd291d77cc90eb6a86e9860ba8e6e38eebd57d12",
                            "lessThan": "493326c4f10cc71a42c27fdc97ce112182ee4cbc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "dd291d77cc90eb6a86e9860ba8e6e38eebd57d12",
                            "lessThan": "d7cb6d7414ea1b33536fa6d11805cb8dceec1f97",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "block/blk-zoned.c",
                        "include/linux/blkdev.h"
                    ],
                    "versions": [
                        {
                            "version": "6.10",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.10",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.5",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.12.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.13"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/493326c4f10cc71a42c27fdc97ce112182ee4cbc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d7cb6d7414ea1b33536fa6d11805cb8dceec1f97"
                }
            ],
            "title": "block: RCU protect disk->conv_zones_bitmap",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}