Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
ubifs: Set page uptodate in the correct place
Page cache reads are lockless, so setting the freshly allocated page uptodate before we’ve overwritten it with the data it’s supposed to have in it will allow a simultaneous reader to see old data. Move the call to SetPageUptodate into ubifs_write_end(), which is after we copied the new data into the page.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Amazon Linux 2 ELS , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 7 ELS , Debian 10 ELS , Oracle Linux 6 ELS , Oracle Linux 7 ELS , RHEL 7 ELS , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- kernel @ 3.10.0 (+17 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 10 | Will Not Fix | — |
| Debian 10 cloud | Will Not Fix | — |
| Debian 11 | Planned | — |
| Debian 12 | Planned | — |
| Proxmox VE 7 5.15 | Released |
45 kernels
|
| Ubuntu 18.04 AWS Focal | In Rollout |
56 kernels
|
| Ubuntu 18.04 HWE Focal | In Rollout |
69 kernels
|
| Ubuntu 20.04 | In Rollout |
110 kernels
|
| Ubuntu 20.04 AWS | In Rollout |
93 kernels
|
| Ubuntu 20.04 Azure | In Rollout |
84 kernels
|
| Ubuntu 20.04 GCP | Planned | — |
| Ubuntu 20.04 HWE AWS | Released |
41 kernels
|
| Ubuntu 20.04 HWE Azure | Released |
25 kernels
|
| Ubuntu 22.04 | Released |
54 kernels
|
| Ubuntu 22.04 AWS | Released |
48 kernels
|
| Ubuntu 22.04 Azure | Released |
45 kernels
|
| Ubuntu 24.04 | Released |
1 kernel
|