CVE-2024-57931
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-57931 affects the Linux kernel's SELinux subsystem, specifically related to the handling of extended permissions. The vulnerability was discovered and disclosed on January 21, 2025. The issue occurs when evaluating extended permissions in SELinux, where unknown permissions would trigger a BUG() call instead of being gracefully handled (NVD).

Technical details

The vulnerability exists in the SELinux subsystem's permission evaluation mechanism. When encountering unknown extended permissions, the system would call BUG() instead of gracefully handling the situation. The fix modifies the behavior to ignore unknown permissions and continue operation, ensuring that future permissions can be added without interfering with older kernels. The patch specifically modifies the servicescomputexperms_decision function in the security/selinux/ss/services.c file (Kernel Commit).

Impact

The vulnerability could potentially cause system crashes when encountering unknown extended permissions in SELinux, affecting system stability and availability. This would occur when new permissions are added in newer kernels but accessed by older kernel versions (Debian Tracker).

Mitigation and workarounds

The issue has been fixed in multiple Linux kernel versions through backported patches. Ubuntu, Debian, and other distributions have released or are in the process of releasing updated kernel packages. Users should update their systems to the patched versions. For Ubuntu, fixes are being worked on for versions 24.04 LTS, 22.04 LTS, and 20.04 LTS (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40085N/AN/A
  • Linux KernelLinux Kernel
  • kernel-abi-whitelists
NoNoOct 29, 2025
CVE-2025-40083N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-internal
NoYesOct 29, 2025
CVE-2023-7324N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesOct 29, 2025
CVE-2025-40082N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoNoOct 28, 2025
CVE-2025-40081N/AN/A
  • Linux KernelLinux Kernel
  • kernel-selftests-internal
NoNoOct 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management