CVE-2024-57917: topology: Keep the cpumask unchanged when printing cpumap
In the Linux kernel, the following vulnerability has been resolved:
topology: Keep the cpumask unchanged when printing cpumap
During fuzz testing, the following warning was discovered:
different return values (15 and 11) from vsnprintf("%*pbl
", ...)
test:keyward is WARNING in kvasprintf
WARNING: CPU: 55 PID: 1168477 at lib/kasprintf.c:30 kvasprintf+0x121/0x130
Call Trace:
kvasprintf+0x121/0x130
kasprintf+0xa6/0xe0
bitmap_print_to_buf+0x89/0x100
core_siblings_list_read+0x7e/0xb0
kernfs_file_read_iter+0x15b/0x270
new_sync_read+0x153/0x260
vfs_read+0x215/0x290
ksys_read+0xb9/0x160
do_syscall_64+0x56/0x100
entry_SYSCALL_64_after_hwframe+0x78/0xe2
The call trace shows that kvasprintf() reported this warning during the
printing of core_siblings_list. kvasprintf() has several steps:
(1) First, calculate the length of the resulting formatted string.
(2) Allocate a buffer based on the returned length.
(3) Then, perform the actual string formatting.
(4) Check whether the lengths of the formatted strings returned in
steps (1) and (2) are consistent.
If the core_cpumask is modified between steps (1) and (3), the lengths
obtained in these two steps may not match. Indeed our test includes cpu
hotplugging, which should modify core_cpumask while printing.
To fix this issue, cache the cpumask into a temporary variable before
calling cpumap_print_{list, cpumask}_to_buf(), to keep it unchanged
during the printing process.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel correctness issue in CPU topology reporting. During CPU hotplug activity, a topology file read can see changing CPU-mask data and trigger a kernel warning. The provided sources do not show remote attack, privilege escalation, data theft, CVSS scoring, or active exploitation.
Executive priority
Treat this as low urgency for typical enterprise patch queues unless affected industrial or embedded products are called out by a vendor. There is no source-backed evidence of exploitation, but kernel updates should still be applied through normal maintenance.
Technical view
The race occurs while printing core_siblings_list/cpumap data. kvasprintf first measures output length, allocates, then formats. If core_cpumask changes between measurement and formatting, return lengths differ and a WARN fires. The kernel fix snapshots the cpumask before printing.
Likely exposure
Systems running affected Linux kernel versions or vendor kernels that include the vulnerable topology code may be exposed. Practical exposure appears tied to local topology reads concurrent with CPU hotplug activity. Vendor appliances should be assessed through their advisories.
Exploitation context
The bundle marks KEV false and includes no cited evidence of active exploitation. The known trigger came from fuzz testing with CPU hotplugging. No public source in the bundle establishes remote exploitation or a complete impact chain.
Researcher notes
The important detail is the time-of-check/time-of-use mismatch in formatted cpumask output, not a memory-corruption proof. Evidence is limited to the kernel fix narrative, CVE metadata, and vendor advisories; impact severity remains unscored in the bundle.
Mitigation direction
Update Linux kernels to versions containing the referenced stable fixes.
Apply distribution or device-vendor kernel updates, including Debian LTS and Siemens guidance where applicable.
For appliances, verify the vendor advisory before assuming upstream kernel fixes are present.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-57917 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
2ADP providers
8Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Jan 19, 2025, 11:52 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.