In the Linux kernel, the following vulnerability has been resolved:
riscv: Sync efi page table's kernel mappings before switching
The EFI page table is initially created as a copy of the kernel page table. With VMAP_STACK enabled, kernel stacks are allocated in the vmalloc area: if the stack is allocated in a new PGD (one that was not present at the moment of the efi page table creation or not synced in a previous vmalloc fault), the kernel will take a trap when switching to the efi page table when the vmalloc kernel stack is accessed, resulting in a kernel panic.
Fix that by updating the efi kernel mappings before switching to the efi page table.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade python-perfUpgrade kernel-tools-debuginfoUpgrade kernel-headersUpgrade kernel-toolsUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade bpftoolUpgrade bpftool-debuginfoUpgrade kernel-tools-develUpgrade kernel-livepatch-5.15.86-53.137Upgrade perf-debuginfoUpgrade kernel-develUpgrade perfUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-aarch64 | Mar 14, 2025 | Oct 21, 2024 |
| Debian | — | Upgrade linux | Oct 23, 2024 | Oct 23, 2024 |
| Ubuntu | — | Upgrade linux-azureUpgrade linuxUpgrade linux-azure-fde-5.15Upgrade linux-raspiUpgrade linux-gkeopUpgrade linux-lowlatencyUpgrade linux-gkeop-5.15Upgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-riscv-5.15Upgrade linux-ibmUpgrade linux-gcpUpgrade linux-azure-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-intel-iotg-5.15Upgrade linux-gcp-5.15Upgrade linux-gkeUpgrade linux-intel-iotgUpgrade linux-intel-iot-realtimeUpgrade linux-aws-5.15Upgrade linux-bluefieldUpgrade linux-azure-fdeUpgrade linux-realtimeUpgrade linux-kvmUpgrade linux-oracle-5.15 | Nov 19, 2024 | Oct 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub