CVE & CISA-KEV Catalog

CVE-2024-57839

MEDIUM
5.5
CVSS v3
NVD

Description

In the Linux kernel, the following vulnerability has been resolved: Revert "readahead: properly shorten readahead when falling back to do_page_cache_ra()" This reverts commit 7c877586da3178974a8a94577b6045a48377ff25. Anders and Philippe have reported that recent kernels occasionally hang when used with NFS in readahead code. The problem has been bisected to 7c877586da3 ("readahead: properly shorten readahead when falling back to do_page_cache_ra()"). The cause of the problem is that ra->size can be shrunk by read_pages() call and subsequently we end up calling do_page_cache_ra() with negative (read huge positive) number of pages. Let's revert 7c877586da3 for now until we can find a proper way how the logic in read_pages() and page_cache_ra_order() can coexist. This can lead to reduced readahead throughput due to readahead window confusion but that's better than outright hangs.

How to fix

Remediation Available
linuxDebian
Fixed in:6.12.5-1CVE-2024-57839
Fixed in:6.12.5-1CVE-2024-57839
linux-hwe-6.11Ubuntu
Fixed in:6.11.0-21.21~24.04.1USN-7379-1
linux-image-6.11.0-1011-lowlatencyUbuntu
Fixed in:6.11.0-1011.12~24.04.1USN-7381-1
linux-image-6.11.0-1011-lowlatency-64kUbuntu
Fixed in:6.11.0-1011.12~24.04.1USN-7381-1
linux-image-6.11.0-1017-oemUbuntu
Fixed in:6.11.0-1017.17USN-7382-1
linux-image-6.11.0-21-genericUbuntu
Fixed in:6.11.0-21.21~24.04.1+1USN-7379-1
linux-image-6.11.0-21-generic-64kUbuntu
Fixed in:6.11.0-21.21~24.04.1+1USN-7379-1
linux-image-generic-64k-hwe-24.04Ubuntu
Fixed in:6.11.0-21.21~24.04.1USN-7379-1
linux-image-generic-hwe-24.04Ubuntu
Fixed in:6.11.0-21.21~24.04.1USN-7379-1
linux-image-lowlatency-64k-hwe-24.04Ubuntu
Fixed in:6.11.0-1011.12~24.04.1USN-7381-1
linux-image-lowlatency-hwe-24.04Ubuntu
Fixed in:6.11.0-1011.12~24.04.1USN-7381-1
linux-image-oem-24.04bUbuntu
Fixed in:6.11.0-1017.17USN-7382-1
linux-image-virtual-hwe-24.04Ubuntu
Fixed in:6.11.0-21.21~24.04.1USN-7379-1
linux-lowlatency-hwe-6.11Ubuntu
Fixed in:6.11.0-1011.12~24.04.1USN-7381-1
linux-oem-6.11Ubuntu
Fixed in:6.11.0-1017.17USN-7382-1

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

0.17%probability of exploitation in 30 days
7thpercentile

Low risk: more likely to be exploited than 7% of all known CVEs.

References

Embed a live status badge for CVE-2024-57839
CVE-2024-57839 severity badge

Markdown

[![CVE-2024-57839](https://tridentstack.com/cve/badge/CVE-2024-57839.svg)](https://tridentstack.com/cve/CVE-2024-57839)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-57839"><img src="https://tridentstack.com/cve/badge/CVE-2024-57839.svg" alt="CVE-2024-57839"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-10-17.