CVE-2024-51729
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-51729 is a vulnerability in the Linux kernel's memory management subsystem, specifically in the copy_user_gigantic_page() function. The issue was discovered when hugetlb_wp() calls copy_user_large_folio() with a fault address that may not be aligned with the huge page size. The vulnerability was identified in October 2024 and affects the Linux kernel's memory management functionality (Kernel Git).

Technical details

The vulnerability stems from copy_user_gigantic_page() requiring the address to be huge page size aligned, while being called with potentially unaligned addresses. This occurs when copy_user_large_folio() passes an unaligned address received from hugetlb_wp(). The technical fix involves modifying the code to ensure proper address alignment using ALIGN_DOWN() and renaming the 'addr' parameter to 'addr_hint' for better clarity (Kernel Git).

Impact

The vulnerability can lead to memory corruption or information leakage in systems utilizing huge pages in the Linux kernel. This could potentially compromise system security and stability (NVD).

Mitigation and workarounds

The issue has been patched in the Linux kernel with commit f5d09de9f1bf. The fix ensures proper address alignment in copy_user_gigantic_page() by using ALIGN_DOWN() with the folio size and introduces clearer parameter naming. Users should update to the patched kernel version (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-internal
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-devel
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management