CVE-2024-53172
Published: Dec 27, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ubi: fastmap: Fix duplicate slab cache names while attaching Since commit 4c39529663b9 ("slab: Warn on duplicate cache names when DEBUG_VM=y"), the duplicate slab cache names can be detected and a kernel WARNING is thrown out. In UBI fast attaching process, alloc_ai() could be invoked twice with the same slab cache name 'ubi_aeb_slab_cache', which will trigger following warning messages: kmem_cache of name 'ubi_aeb_slab_cache' already exists WARNING: CPU: 0 PID: 7519 at mm/slab_common.c:107 __kmem_cache_create_args+0x100/0x5f0 Modules linked in: ubi(+) nandsim [last unloaded: nandsim] CPU: 0 UID: 0 PID: 7519 Comm: modprobe Tainted: G 6.12.0-rc2 RIP: 0010:__kmem_cache_create_args+0x100/0x5f0 Call Trace: __kmem_cache_create_args+0x100/0x5f0 alloc_ai+0x295/0x3f0 [ubi] ubi_attach+0x3c3/0xcc0 [ubi] ubi_attach_mtd_dev+0x17cf/0x3fa0 [ubi] ubi_init+0x3fb/0x800 [ubi] do_init_module+0x265/0x7d0 __x64_sys_finit_module+0x7a/0xc0 The problem could be easily reproduced by loading UBI device by fastmap with CONFIG_DEBUG_VM=y. Fix it by using different slab names for alloc_ai() callers.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected d2158f69a7d469c21c37f7028c18aa8c54707de3 - < ef52b7191ac41e68b1bf070d00c5b04ed16e4920affected d2158f69a7d469c21c37f7028c18aa8c54707de3 - < 871c148f8e0c32e505df9393ba4a303c3c3fe988affected d2158f69a7d469c21c37f7028c18aa8c54707de3 - < 04c0b0f37617099479c34e207c5550d081f585a6affected d2158f69a7d469c21c37f7028c18aa8c54707de3 - < b1ee0aa4945c49cbbd779da81040fcec4de80fd1affected d2158f69a7d469c21c37f7028c18aa8c54707de3 - < 6afdcb285794e75d2c8995e3a44f523c176cc2de+4 more versions |
Linux | Linux | affected 4.1unaffected 0 - < 4.1unaffected 4.19.325 - <= 4.19.*unaffected 5.4.287 - <= 5.4.*unaffected 5.10.231 - <= 5.10.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now