{"id":"DEBIAN-CVE-2024-35797","details":"In the Linux kernel, the following vulnerability has been resolved:  mm: cachestat: fix two shmem bugs  When cachestat on shmem races with swapping and invalidation, there are two possible bugs:  1) A swapin error can have resulted in a poisoned swap entry in the    shmem inode's xarray. Calling get_shadow_from_swap_cache() on it    will result in an out-of-bounds access to swapper_spaces[].     Validate the entry with non_swap_entry() before going further.  2) When we find a valid swap entry in the shmem's inode, the shadow    entry in the swapcache might not exist yet: swap IO is still in    progress and we're before __remove_mapping; swapin, invalidation,    or swapoff have removed the shadow from swapcache after we saw the    shmem swap entry.     This will send a NULL to workingset_test_recent(). The latter    purely operates on pointer bits, so it won't crash - node 0, memcg    ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a    bogus test. In theory that could result in a false \"recently    evicted\" count.     Such a false positive wouldn't be the end of the world. But for    code clarity and (future) robustness, be explicit about this case.     Bail on get_shadow_from_swap_cache() returning NULL.","modified":"2026-09-15T09:03:07.577966338Z","published":"2024-05-17T14:15:11.937Z","upstream":["CVE-2024-35797"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-35797"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35797.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35797.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}