CVE-2024-26906: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault()
In the Linux kernel, the following vulnerability has been resolved:
x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault()
When trying to use copy_from_kernel_nofault() to read vsyscall page
through a bpf program, the following oops was reported:
BUG: unable to handle page fault for address: ffffffffff600000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 3231067 P4D 3231067 PUD 3233067 PMD 3235067 PTE 0
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 1 PID: 20390 Comm: test_progs ...... 6.7.0+ #58
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......
RIP: 0010:copy_from_kernel_nofault+0x6f/0x110
......
Call Trace:
<TASK>
? copy_from_kernel_nofault+0x6f/0x110
bpf_probe_read_kernel+0x1d/0x50
bpf_prog_2061065e56845f08_do_probe_read+0x51/0x8d
trace_call_bpf+0xc5/0x1c0
perf_call_bpf_enter.isra.0+0x69/0xb0
perf_syscall_enter+0x13e/0x200
syscall_trace_enter+0x188/0x1c0
do_syscall_64+0xb5/0xe0
entry_SYSCALL_64_after_hwframe+0x6e/0x76
</TASK>
......
---[ end trace 0000000000000000 ]---
The oops is triggered when:
1) A bpf program uses bpf_probe_read_kernel() to read from the vsyscall
page and invokes copy_from_kernel_nofault() which in turn calls
__get_user_asm().
2) Because the vsyscall page address is not readable from kernel space,
a page fault exception is triggered accordingly.
3) handle_page_fault() considers the vsyscall page address as a user
space address instead of a kernel space address. This results in the
fix-up setup by bpf not being applied and a page_fault_oops() is invoked
due to SMAP.
Considering handle_page_fault() has already considered the vsyscall page
address as a userspace address, fix the problem by disallowing vsyscall
page read for copy_from_kernel_nofault().
Security readout for executives and security teams
Plain-English summary
CVE-2024-26906 is a Linux kernel stability issue where a BPF read of the legacy vsyscall page can trigger a kernel oops. The source describes a crash path, not remote code execution or data theft. Business impact is mainly availability risk on affected Linux systems that allow such BPF activity.
Executive priority
Prioritize in normal kernel maintenance, with higher urgency for shared or multi-tenant Linux hosts where local BPF access is possible. The current evidence supports availability risk, not confirmed remote compromise. Patch through supported vendor channels and verify deployment.
Technical view
The fault occurs when bpf_probe_read_kernel() reaches copy_from_kernel_nofault() on the vsyscall address. The address is treated as userspace by handle_page_fault(), so the BPF fixup is not applied and page_fault_oops() is reached under SMAP. The kernel fix disallows vsyscall page reads through copy_from_kernel_nofault().
Likely exposure
Exposure is Linux systems running affected kernel branches before the referenced stable fixes, especially hosts where local users, containers, or services can execute BPF/perf tracing paths. Confirm using distribution kernel advisories because vendor kernels backport fixes and the source bundle does not enumerate all package versions.
Exploitation context
No KEV listing or supplied source indicates active exploitation. The described trigger is local BPF-driven behavior that produced a kernel oops in testing. Sources do not claim unauthenticated remote exploitation, privilege escalation, or public weaponization.
Researcher notes
The source evidence is narrowly scoped to x86/mm vsyscall handling and BPF probe reads. Affected version metadata is limited and should be reconciled with downstream kernel backports. Do not assume exploitability beyond the documented kernel oops without additional vendor analysis.
Mitigation direction
Apply Linux kernel updates containing the referenced stable commits or distribution backports.
Review Debian LTS and Siemens advisories if those platforms are in scope.
Restrict unnecessary local BPF/perf tracing access according to existing hardening policy.
Prioritize exposed multi-tenant, shared shell, container, and build systems.
Track vendor guidance for exact fixed package versions.
Validation and detection
Inventory Linux kernel versions across servers, appliances, container hosts, and developer systems.
Map versions to vendor advisories and the referenced stable kernel fixes.
Check whether untrusted users or workloads can load or trigger BPF programs.
Review crash logs for kernel oopses involving copy_from_kernel_nofault or bpf_probe_read_kernel.
Confirm patched kernels remain deployed after reboot.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-26906 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.