In the Linux kernel, the following vulnerability has been resolved: procfs: fix possible double mmput() in do_procmap_query() When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY we return with -ENAMETOOLONG error. After recent changes this condition happens later, after we unlocked mmap_lock/per-VMA lock and did mmput(), so original goto out is now wrong and will double-mmput() mm_struct. Fix by jumping further to clean up only vm_file and name_buf.
Update Linux/Linux to f9fe092084cd04deea18747f58a2304026e76aaa if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanprocfs: fix possible double mmput() in do_procmap_query() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: procfs: fix possible double mmput() in do_procmap_query() When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY we return with -ENAMETOOLONG error. After recent changes this condition happens later, after we unlocked mmap_lock/per-VMA lock and did mmput(), so original goto out is now wrong and will double-mmput() mm_struct. Fix by jumping further to clean up only vm_file and name_buf.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b9b97e6aeb534315f9646b2090d1a5024c6a4e82 <f9fe092084cd04deea18747f58a2304026e76aaa || >=cbc03ce3e6ce7e21214c3f02218213574c1a2d08 <8adaff87db143583e08eec4f4e7788f1ef8af94d || >=b5cbacd7f86f4f62b8813688c8e73be94e8e1951 <90f5e87c9b75833b9ef3a4415b92c0247f28ab2f || >=b5cbacd7f86f4f62b8813688c8e73be94e8e1951 <61dc9f776705d6db6847c101b98fa4f0e9eb6fa3 || >=6.12.70 <6.12.75 || >=6.18.10 <6.18.16 |
In the Linux kernel, the following vulnerability has been resolved: procfs: fix possible double mmput() in do_procmap_query() When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY we return with -ENAMETOOLONG error. After recent changes this condition happens later, after we unlocked mmap_lock/per-VMA lock and did mmput(), so original goto out is now wrong and will double-mmput() mm_struct. Fix by jumping further to clean up only vm_file and name_buf.
Update Linux/Linux to f9fe092084cd04deea18747f58a2304026e76aaa if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanprocfs: fix possible double mmput() in do_procmap_query() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: procfs: fix possible double mmput() in do_procmap_query() When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY we return with -ENAMETOOLONG error. After recent changes this condition happens later, after we unlocked mmap_lock/per-VMA lock and did mmput(), so original goto out is now wrong and will double-mmput() mm_struct. Fix by jumping further to clean up only vm_file and name_buf.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b9b97e6aeb534315f9646b2090d1a5024c6a4e82 <f9fe092084cd04deea18747f58a2304026e76aaa || >=cbc03ce3e6ce7e21214c3f02218213574c1a2d08 <8adaff87db143583e08eec4f4e7788f1ef8af94d || >=b5cbacd7f86f4f62b8813688c8e73be94e8e1951 <90f5e87c9b75833b9ef3a4415b92c0247f28ab2f || >=b5cbacd7f86f4f62b8813688c8e73be94e8e1951 <61dc9f776705d6db6847c101b98fa4f0e9eb6fa3 || >=6.12.70 <6.12.75 || >=6.18.10 <6.18.16 |
| f9fe092084cd04deea18747f58a2304026e76aaa, 8adaff87db143583e08eec4f4e7788f1ef8af94d, 90f5e87c9b75833b9ef3a4415b92c0247f28ab2f, 61dc9f776705d6db6847c101b98fa4f0e9eb6fa3, 6.12.75, 6.18.16 |
| Linux/Linuxgeneric | 6.19 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| f9fe092084cd04deea18747f58a2304026e76aaa, 8adaff87db143583e08eec4f4e7788f1ef8af94d, 90f5e87c9b75833b9ef3a4415b92c0247f28ab2f, 61dc9f776705d6db6847c101b98fa4f0e9eb6fa3, 6.12.75, 6.18.16 |
| Linux/Linuxgeneric | 6.19 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard