In the Linux kernel, the following vulnerability has been resolved:
slub/kunit: fix a WARNING due to unwrapped __kmalloc_cache_noprof
'modprobe slub_kunit' will have a warning as shown below. The root cause is that __kmalloc_cache_noprof was directly used, which resulted in no alloc_tag being allocated. This caused current->alloc_tag to be null, leading to a warning in alloc_tag_add_check.
Let's add an alloc_hook layer to __kmalloc_cache_noprof specifically within lib/slub_kunit.c, which is the only user of this internal slub function outside kmalloc implementation itself.
[58162.947016] WARNING: CPU: 2 PID: 6210 at ./include/linux/alloc_tag.h:125 alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.957721] Call trace: [58162.957919] alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.958286] __kmalloc_cache_noprof+0x14c/0x344 [58162.958615] test_kmalloc_redzone_access+0x50/0x10c [slub_kunit] [58162.959045] kunit_try_run_case+0x74/0x184 [kunit] [58162.959401] kunit_generic_run_threadfn_adapter+0x2c/0x4c [kunit] [58162.959841] kthread+0x10c/0x118 [58162.960093] ret_from_fork+0x10/0x20 [58162.960363] ---[ end trace 0000000000000000 ]---
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-virtualUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-awsUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-lowlatencyUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oem-24.04bUpgrade linux-image-realtimeUpgrade linux-image-oem-24.04Upgrade linux-image-azure-fdeUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.11.0-1015-oemUpgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-oracle-64kUpgrade linux-image-generic | Feb 20, 2025 | Nov 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub