<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:30:16 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-40915 — riscv: rewrite __kernel_map_pages() to fix sleeping in invalid context</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-40915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;riscv: rewrite __kernel_map_pages() to fix sleeping in invalid context&lt;/p&gt;
&lt;p&gt;__kernel_map_pages() is a debug function which clears the valid bit in page
table entry for deallocated pages to detect illegal memory accesses to
freed pages.&lt;/p&gt;
&lt;p&gt;This function set/clear the valid bit using __set_memory(). __set_memory()
acquires init_mm&amp;#39;s semaphore, and this operation may sleep. This is
problematic, because  __kernel_map_pages() can be called in atomic context,
and thus is illegal to sleep. An example warning that this causes:&lt;/p&gt;
&lt;p&gt;BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1578
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd
preempt_count: 2, expected: 0
CPU: 0 PID: 2 Comm: kthreadd Not tainted 6.9.0-g1d4c6d784ef6 #37
Hardware name: riscv-virtio,qemu (DT)
Call Trace:
[&amp;lt;ffffffff800060dc&amp;gt;] dump_backtrace+0x1c/0x24
[&amp;lt;ffffffff8091ef6e&amp;gt;] show_stack+0x2c/0x38
[&amp;lt;ffffffff8092baf8&amp;gt;] dump_stack_lvl+0x5a/0x72
[&amp;lt;ffffffff8092bb24&amp;gt;] dump_stack+0x14/0x1c
[&amp;lt;ffffffff8003b7ac&amp;gt;] __might_resched+0x104/0x10e
[&amp;lt;ffffffff8003b7f4&amp;gt;] __might_sleep+0x3e/0x62
[&amp;lt;ffffffff8093276a&amp;gt;] down_write+0x20/0x72
[&amp;lt;ffffffff8000cf00&amp;gt;] __set_memory+0x82/0x2fa
[&amp;lt;ffffffff8000d324&amp;gt;] __kernel_map_pages+0x5a/0xd4
[&amp;lt;ffffffff80196cca&amp;gt;] __alloc_pages_bulk+0x3b2/0x43a
[&amp;lt;ffffffff8018ee82&amp;gt;] __vmalloc_node_range+0x196/0x6ba
[&amp;lt;ffffffff80011904&amp;gt;] copy_process+0x72c/0x17ec
[&amp;lt;ffffffff80012ab4&amp;gt;] kernel_clone+0x60/0x2fe
[&amp;lt;fff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;riscv: rewrite __kernel_map_pages() to fix sleeping in invalid context&lt;/p&gt;
&lt;p&gt;__kernel_map_pages() is a debug function which clears the valid bit in page
table entry for deallocated pages to detect illegal memory accesses to
freed pages.&lt;/p&gt;
&lt;p&gt;This function set/clear the valid bit using __set_memory(). __set_memory()
acquires init_mm&amp;#39;s semaphore, and this operation may sleep. This is
problematic, because  __kernel_map_pages() can be called in atomic context,
and thus is illegal to sleep. An example warning that this causes:&lt;/p&gt;
&lt;p&gt;BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1578
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd
preempt_count: 2, expected: 0
CPU: 0 PID: 2 Comm: kthreadd Not tainted 6.9.0-g1d4c6d784ef6 #37
Hardware name: riscv-virtio,qemu (DT)
Call Trace:
[&amp;lt;ffffffff800060dc&amp;gt;] dump_backtrace+0x1c/0x24
[&amp;lt;ffffffff8091ef6e&amp;gt;] show_stack+0x2c/0x38
[&amp;lt;ffffffff8092baf8&amp;gt;] dump_stack_lvl+0x5a/0x72
[&amp;lt;ffffffff8092bb24&amp;gt;] dump_stack+0x14/0x1c
[&amp;lt;ffffffff8003b7ac&amp;gt;] __might_resched+0x104/0x10e
[&amp;lt;ffffffff8003b7f4&amp;gt;] __might_sleep+0x3e/0x62
[&amp;lt;ffffffff8093276a&amp;gt;] down_write+0x20/0x72
[&amp;lt;ffffffff8000cf00&amp;gt;] __set_memory+0x82/0x2fa
[&amp;lt;ffffffff8000d324&amp;gt;] __kernel_map_pages+0x5a/0xd4
[&amp;lt;ffffffff80196cca&amp;gt;] __alloc_pages_bulk+0x3b2/0x43a
[&amp;lt;ffffffff8018ee82&amp;gt;] __vmalloc_node_range+0x196/0x6ba
[&amp;lt;ffffffff80011904&amp;gt;] copy_process+0x72c/0x17ec
[&amp;lt;ffffffff80012ab4&amp;gt;] kernel_clone+0x60/0x2fe
[&amp;lt;fff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-40915</guid>
    </item>
  </channel>
</rss>
