<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 19:21:09 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-26688 — fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-26688</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super&lt;/p&gt;
&lt;p&gt;When configuring a hugetlb filesystem via the fsconfig() syscall, there is
a possible NULL dereference in hugetlbfs_fill_super() caused by assigning
NULL to ctx-&amp;gt;hstate in hugetlbfs_parse_param() when the requested pagesize
is non valid.&lt;/p&gt;
&lt;p&gt;E.g: Taking the following steps:&lt;/p&gt;
&lt;p&gt;fd = fsopen(&amp;#34;hugetlbfs&amp;#34;, FSOPEN_CLOEXEC);
     fsconfig(fd, FSCONFIG_SET_STRING, &amp;#34;pagesize&amp;#34;, &amp;#34;1024&amp;#34;, 0);
     fsconfig(fd, FSCONFIG_CMD_CREATE, NULL, NULL, 0);&lt;/p&gt;
&lt;p&gt;Given that the requested &amp;#34;pagesize&amp;#34; is invalid, ctxt-&amp;gt;hstate will be replaced
with NULL, losing its previous value, and we will print an error:&lt;/p&gt;
&lt;p&gt;...
 ...
 case Opt_pagesize:
 ps = memparse(param-&amp;gt;string, &amp;amp;rest);
 ctx-&amp;gt;hstate = h;
 if (!ctx-&amp;gt;hstate) {
         pr_err(&amp;#34;Unsupported page size %lu MB\n&amp;#34;, ps / SZ_1M);
         return -EINVAL;
 }
 return 0;
 ...
 ...&lt;/p&gt;
&lt;p&gt;This is a problem because later on, we will dereference ctxt-&amp;gt;hstate in
hugetlbfs_fill_super()&lt;/p&gt;
&lt;p&gt;...
 ...
 sb-&amp;gt;s_blocksize = huge_page_size(ctx-&amp;gt;hstate);
 ...
 ...&lt;/p&gt;
&lt;p&gt;Causing below Oops.&lt;/p&gt;
&lt;p&gt;Fix this by replacing cxt-&amp;gt;hstate value only when then pagesize is known
to be valid.&lt;/p&gt;
&lt;p&gt;kernel: hugetlbfs: Unsupported page size 0 MB
 kernel: BUG: kernel NULL pointer dereference, address: 0000000000000028
 kernel: #PF: supervisor read access in kernel mode
 kernel: #PF: error_code(0x0000) - not-present page
 kernel: PGD 800000010f66c067 P4D 800000010f66c067 PUD 1b22f8067…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super&lt;/p&gt;
&lt;p&gt;When configuring a hugetlb filesystem via the fsconfig() syscall, there is
a possible NULL dereference in hugetlbfs_fill_super() caused by assigning
NULL to ctx-&amp;gt;hstate in hugetlbfs_parse_param() when the requested pagesize
is non valid.&lt;/p&gt;
&lt;p&gt;E.g: Taking the following steps:&lt;/p&gt;
&lt;p&gt;fd = fsopen(&amp;#34;hugetlbfs&amp;#34;, FSOPEN_CLOEXEC);
     fsconfig(fd, FSCONFIG_SET_STRING, &amp;#34;pagesize&amp;#34;, &amp;#34;1024&amp;#34;, 0);
     fsconfig(fd, FSCONFIG_CMD_CREATE, NULL, NULL, 0);&lt;/p&gt;
&lt;p&gt;Given that the requested &amp;#34;pagesize&amp;#34; is invalid, ctxt-&amp;gt;hstate will be replaced
with NULL, losing its previous value, and we will print an error:&lt;/p&gt;
&lt;p&gt;...
 ...
 case Opt_pagesize:
 ps = memparse(param-&amp;gt;string, &amp;amp;rest);
 ctx-&amp;gt;hstate = h;
 if (!ctx-&amp;gt;hstate) {
         pr_err(&amp;#34;Unsupported page size %lu MB\n&amp;#34;, ps / SZ_1M);
         return -EINVAL;
 }
 return 0;
 ...
 ...&lt;/p&gt;
&lt;p&gt;This is a problem because later on, we will dereference ctxt-&amp;gt;hstate in
hugetlbfs_fill_super()&lt;/p&gt;
&lt;p&gt;...
 ...
 sb-&amp;gt;s_blocksize = huge_page_size(ctx-&amp;gt;hstate);
 ...
 ...&lt;/p&gt;
&lt;p&gt;Causing below Oops.&lt;/p&gt;
&lt;p&gt;Fix this by replacing cxt-&amp;gt;hstate value only when then pagesize is known
to be valid.&lt;/p&gt;
&lt;p&gt;kernel: hugetlbfs: Unsupported page size 0 MB
 kernel: BUG: kernel NULL pointer dereference, address: 0000000000000028
 kernel: #PF: supervisor read access in kernel mode
 kernel: #PF: error_code(0x0000) - not-present page
 kernel: PGD 800000010f66c067 P4D 800000010f66c067 PUD 1b22f8067…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-26688</guid>
    </item>
  </channel>
</rss>
