In the Linux kernel, the following vulnerability has been resolved:
maple_tree: correct tree corruption on spanning store
Patch series "maple_tree: correct tree corruption on spanning store", v3.
There has been a nasty yet subtle maple tree corruption bug that appears to have been in existence since the inception of the algorithm.
This bug seems far more likely to happen since commit f8d112a4e657 ("mm/mmap: avoid zeroing vma tree in mmap_region()"), which is the point at which reports started to be submitted concerning this bug.
We were made definitely aware of the bug thanks to the kind efforts of Bert Karwatzki who helped enormously in my being able to track this down and identify the cause of it.
The bug arises when an attempt is made to perform a spanning store across two leaf nodes, where the right leaf node is the rightmost child of the shared parent, AND the store completely consumes the right-mode node.
This results in mas_wr_spanning_store() mitakenly duplicating the new and existing entries at the maximum pivot within the range, and thus maple tree corruption.
The fix patch corrects this by detecting this scenario and disallowing the mistaken duplicate copy.
The fix patch commit message goes into great detail as to how this occurs.
This series also includes a test which reliably reproduces the issue, and asserts that the fix works correctly.
Bert has kindly tested the fix and confirmed it resolved his issues. Also Mikhail Gavrilov kindly reported what appears to be precisely the same bug, which this fix should also resolve.
This patch (of 2):
There has been a subtle bug present in the maple tree implementation from its inception.
This arises from how stores are performed - when a store occurs, it will overwrite overlapping ranges and adjust the tree as necessary to accommodate this.
A range may always ultimately span two leaf nodes. In this instance we walk the two leaf nodes, determine which elements are not overwritten to the left and to the right of the start and end of the ranges respectively and then rebalance the tree to contain these entries and the newly inserted one.
This kind of store is dubbed a 'spanning store' and is implemented by mas_wr_spanning_store().
In order to reach this stage, mas_store_gfp() invokes mas_wr_preallocate(), mas_wr_store_type() and mas_wr_walk() in turn to walk the tree and update the object (mas) to traverse to the location where the write should be performed, determining its store type.
When a spanning store is required, this function returns false stopping at the parent node which contains the target range, and mas_wr_store_type() marks the mas->store_type as wr_spanning_store to denote this fact.
When we go to perform the store in mas_wr_spanning_store(), we first determine the elements AFTER the END of the range we wish to store (that is, to the right of the entry to be inserted) - we do this by walking to the NEXT pivot in the tree (i.e. r_mas.last + 1), starting at the node we have just determined contains the range over which we intend to write.
We then turn our attention to the entries to the left of the entry we are inserting, whose state is represented by l_mas, and copy these into a 'big node', which is a special node which contains enough slots to contain two leaf node's worth of data.
We then copy the entry we wish to store immediately after this - the copy and the insertion of the new entry is performed by mas_store_b_node().
After this we copy the elements to the right of the end of the range which we are inserting, if we have not exceeded the length of the node (i.e. r_mas.offset <= r_mas.end).
Herein lies the bug - under very specific circumstances, this logic can break and corrupt the maple tree.
Consider the following tree:
Height 0 Root Node / \ pivot = 0xffff / \ pivot = ULONG_MAX / ---truncated---
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-develUpgrade python3-perf-debuginfoUpgrade kernelUpgrade kernel-modules-extraUpgrade bpftool-debuginfoUpgrade kernel-livepatch-6.1.115-126.197Upgrade kernel-tools-debuginfoUpgrade kernel-libbpf-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-libbpfUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade bpftoolUpgrade kernel-libbpf-staticUpgrade perfUpgrade python3-perfUpgrade kernel-modules-extra-commonUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade kernel-tools-develUpgrade kernel-headers | Mar 27, 2025 | Nov 8, 2024 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Nov 11, 2024 | Nov 8, 2024 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | May 15, 2025 | Nov 8, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1025-azure-fdeUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-gcp-64kUpgrade linux-image-nvidia-6.8Upgrade linux-image-oem-24.04bUpgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1025-azureUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-6.8.0-2023-raspi-realtimeUpgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-56-genericUpgrade linux-image-6.8.0-1024-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1022-oracle-64kUpgrade linux-image-6.8.0-1024-oemUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-oem-22.04cUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-realtimeUpgrade linux-image-gkeopUpgrade linux-image-nvidiaUpgrade linux-image-genericUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-1026-gcpUpgrade linux-image-6.8.0-1028-raspiUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-raspiUpgrade linux-image-6.8.0-1026-gcp-64kUpgrade linux-image-6.8.0-57-genericUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1021-gkeUpgrade linux-image-6.8.0-56-lowlatencyUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-oem-22.04Upgrade linux-image-gkeUpgrade linux-image-6.8.0-1024-nvidia-lowlatencyUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-azure-nvidiaUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-6.8.0-1022-ibmUpgrade linux-image-gcp-lts-24.04Upgrade linux-image-6.8.0-56-lowlatency-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-6.8.0-1022-oracleUpgrade linux-image-aws-lts-24.04Upgrade linux-image-6.8.0-1024-nvidiaUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-azure-lts-24.04Upgrade linux-image-6.8.0-1014-azure-nvidiaUpgrade linux-image-6.8.1-1018-realtimeUpgrade linux-image-oem-22.04bUpgrade linux-image-azure-fdeUpgrade linux-image-gcpUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-azureUpgrade linux-image-oracle-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-raspi-realtimeUpgrade linux-image-virtualUpgrade linux-image-oem-22.04aUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-1008-gkeopUpgrade linux-image-kvmUpgrade linux-image-6.8.0-1024-nvidia-64kUpgrade linux-image-gkeop-6.8Upgrade linux-image-6.8.0-1025-awsUpgrade linux-image-ibmUpgrade linux-image-ibm-classicUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.8.0-57-generic-64kUpgrade linux-image-6.8.0-56-generic-64kUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-awsUpgrade linux-image-6.8.0-1027-aws | Feb 20, 2025 | Nov 8, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 14, 2025 | Nov 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub