{"id":"DEBIAN-CVE-2024-46847","details":"In the Linux kernel, the following vulnerability has been resolved:  mm: vmalloc: ensure vmap_block is initialised before adding to queue  Commit 8c61291fd850 (\"mm: fix incorrect vbq reference in purge_fragmented_block\") extended the 'vmap_block' structure to contain a 'cpu' field which is set at allocation time to the id of the initialising CPU.  When a new 'vmap_block' is being instantiated by new_vmap_block(), the partially initialised structure is added to the local 'vmap_block_queue' xarray before the 'cpu' field has been initialised.  If another CPU is concurrently walking the xarray (e.g.  via vm_unmap_aliases()), then it may perform an out-of-bounds access to the remote queue thanks to an uninitialised index.  This has been observed as UBSAN errors in Android:   | Internal error: UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP  |  | Call trace:  |  purge_fragmented_block+0x204/0x21c  |  _vm_unmap_aliases+0x170/0x378  |  vm_unmap_aliases+0x1c/0x28  |  change_memory_common+0x1dc/0x26c  |  set_memory_ro+0x18/0x24  |  module_enable_ro+0x98/0x238  |  do_init_module+0x1b0/0x310  Move the initialisation of 'vb-\u003ecpu' in new_vmap_block() ahead of the addition to the xarray.","modified":"2026-09-15T09:03:15.065734490Z","published":"2024-09-27T13:15:16.570Z","upstream":["CVE-2024-46847"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-46847"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46847.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46847.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}