CVE-2024-36000

mm/hugetlb: fix missing hugetlb_lock for resv uncharge

References

Notes

 carnil> Introduced in 79aa925bf239 ("hugetlb_cgroup: fix reservation accounting").
 carnil> Vulnerable versions: 5.9.7 5.10-rc3.

Bugs

Status

Branch Status
upstream released (6.9-rc6) [b76b46902c2d0395488c8412e1116c2486cdfcb2]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.8-upstream-stable released (6.8.9) [538faabf31e9c53d8c870d114846fda958a0de10]
6.6-upstream-stable released (6.6.30) [f6c5d21db16a0910152ec8aa9d5a7aed72694505]
6.1-upstream-stable released (6.1.91) [4c806333efea1000a2a9620926f560ad2e1ca7cc]
5.10-upstream-stable needed
4.19-upstream-stable N/A "Vulnerable code not present"
sid released (6.8.9-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.94-1)
5.10-bullseye-security needed
4.19-buster-security N/A "Vulnerable code not present"