vulnerability
Ubuntu: (CVE-2024-27406): linux-raspi-realtime vulnerability
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:N/C:N/I:N/A:C) | May 17, 2024 | Feb 11, 2025 | May 22, 2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:C)
Published
May 17, 2024
Added
Feb 11, 2025
Modified
May 22, 2025
Description
In the Linux kernel, the following vulnerability has been resolved:
lib/Kconfig.debug: TEST_IOV_ITER depends on MMU
Trying to run the iov_iter unit test on a nommu system such as the qemu
kc705-nommu emulation results in a crash.
KTAP version 1
# Subtest: iov_iter
# module: kunit_iov_iter
1..9
BUG: failure at mm/nommu.c:318/vmap()!
Kernel panic - not syncing: BUG!
The test calls vmap() directly, but vmap() is not supported on nommu
systems, causing the crash. TEST_IOV_ITER therefore needs to depend on
MMU.
Solution
ubuntu-upgrade-linux-raspi-realtime
References
- CVE-2024-27406
- https://attackerkb.com/topics/CVE-2024-27406
- URL-https://git.kernel.org/linus/1eb1e984379e2da04361763f66eec90dd75cf63e
- URL-https://git.kernel.org/stable/c/1eb1e984379e2da04361763f66eec90dd75cf63e
- URL-https://git.kernel.org/stable/c/9e6e541b97762d5b1143070067f7c68f39a408f8
- URL-https://git.kernel.org/stable/c/e6316749d603fe9c4c91f6ec3694e06e4de632a3
- URL-https://www.cve.org/CVERecord?id=CVE-2024-27406

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.