{"id":"DEBIAN-CVE-2024-26989","details":"In the Linux kernel, the following vulnerability has been resolved:  arm64: hibernate: Fix level3 translation fault in swsusp_save()  On arm64 machines, swsusp_save() faults if it attempts to access MEMBLOCK_NOMAP memory ranges. This can be reproduced in QEMU using UEFI when booting with rodata=off debug_pagealloc=off and CONFIG_KFENCE=n:    Unable to handle kernel paging request at virtual address ffffff8000000000   Mem abort info:     ESR = 0x0000000096000007     EC = 0x25: DABT (current EL), IL = 32 bits     SET = 0, FnV = 0     EA = 0, S1PTW = 0     FSC = 0x07: level 3 translation fault   Data abort info:     ISV = 0, ISS = 0x00000007, ISS2 = 0x00000000     CM = 0, WnR = 0, TnD = 0, TagAccess = 0     GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0   swapper pgtable: 4k pages, 39-bit VAs, pgdp=00000000eeb0b000   [ffffff8000000000] pgd=180000217fff9803, p4d=180000217fff9803, pud=180000217fff9803, pmd=180000217fff8803, pte=0000000000000000   Internal error: Oops: 0000000096000007 [#1] SMP   Internal error: Oops: 0000000096000007 [#1] SMP   Modules linked in: xt_multiport ipt_REJECT nf_reject_ipv4 xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c iptable_filter bpfilter rfkill at803x snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg dwmac_generic stmmac_platform snd_hda_codec stmmac joydev pcs_xpcs snd_hda_core phylink ppdev lp parport ramoops reed_solomon ip_tables x_tables nls_iso8859_1 vfat multipath linear amdgpu amdxcp drm_exec gpu_sched drm_buddy hid_generic usbhid hid radeon video drm_suballoc_helper drm_ttm_helper ttm i2c_algo_bit drm_display_helper cec drm_kms_helper drm   CPU: 0 PID: 3663 Comm: systemd-sleep Not tainted 6.6.2+ #76   Source Version: 4e22ed63a0a48e7a7cff9b98b7806d8d4add7dc0   Hardware name: Greatwall GW-XXXXXX-XXX/GW-XXXXXX-XXX, BIOS KunLun BIOS V4.0 01/19/2021   pstate: 600003c5 (nZCv DAIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)   pc : swsusp_save+0x280/0x538   lr : swsusp_save+0x280/0x538   sp : ffffffa034a3fa40   x29: ffffffa034a3fa40 x28: ffffff8000001000 x27: 0000000000000000   x26: ffffff8001400000 x25: ffffffc08113e248 x24: 0000000000000000   x23: 0000000000080000 x22: ffffffc08113e280 x21: 00000000000c69f2   x20: ffffff8000000000 x19: ffffffc081ae2500 x18: 0000000000000000   x17: 6666662074736420 x16: 3030303030303030 x15: 3038666666666666   x14: 0000000000000b69 x13: ffffff9f89088530 x12: 00000000ffffffea   x11: 00000000ffff7fff x10: 00000000ffff7fff x9 : ffffffc08193f0d0   x8 : 00000000000bffe8 x7 : c0000000ffff7fff x6 : 0000000000000001   x5 : ffffffa0fff09dc8 x4 : 0000000000000000 x3 : 0000000000000027   x2 : 0000000000000000 x1 : 0000000000000000 x0 : 000000000000004e   Call trace:    swsusp_save+0x280/0x538    swsusp_arch_suspend+0x148/0x190    hibernation_snapshot+0x240/0x39c    hibernate+0xc4/0x378    state_store+0xf0/0x10c    kobj_attr_store+0x14/0x24  The reason is swsusp_save() -\u003e copy_data_pages() -\u003e page_is_saveable() -\u003e kernel_page_present() assuming that a page is always present when can_set_direct_map() is false (all of rodata_full, debug_pagealloc_enabled() and arm64_kfence_can_set_direct_map() false), irrespective of the MEMBLOCK_NOMAP ranges. Such MEMBLOCK_NOMAP regions should not be saved during hibernation.  This problem was introduced by changes to the pfn_valid() logic in commit a7d9f306ba70 (\"arm64: drop pfn_valid_within() and simplify pfn_valid()\").  Similar to other architectures, drop the !can_set_direct_map() check in kernel_page_present() so that page_is_savable() skips such pages.  [catalin.marinas@arm.com: rework commit message]","modified":"2026-09-15T09:03:06.049426524Z","published":"2024-05-01T06:15:16.577Z","upstream":["CVE-2024-26989"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26989"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.90-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26989.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26989.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26989.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}