From: Junjie Cao <junjie.cao@linux.dev>
To: openembedded-core@lists.openembedded.org
Cc: paul@pbarker.dev, randy.macleod@windriver.com,
Venkata.Navuduri@windriver.com
Subject: [OE-core][PATCH v2 02/10] cve-exclusion: set status for CVE-2021-3714
Date: Mon, 3 Aug 2026 01:48:19 -0700 [thread overview]
Message-ID: <20260803084827.1348810-3-junjie.cao@linux.dev> (raw)
In-Reply-To: <20260803084827.1348810-1-junjie.cao@linux.dev>
KSM merges identical anonymous pages across processes. An attacker who
can place chosen page-sized content in a victim's memory can detect the
merge through the timing of the resulting copy-on-write fault, and so
leak memory contents remotely.
This cannot be fixed without removing deduplication, and the affected
projects have said so explicitly. Red Hat closed the issue WONTFIX:
https://bugzilla.redhat.com/show_bug.cgi?id=1931327
Debian marks src:linux unfixed with the note "Inherent design
limitation, can be avoided by not using KSM":
https://security-tracker.debian.org/tracker/CVE-2021-3714
Ubuntu records "there is no upstream fix available as of 2024-06-17" and
lists disabling KSM as the only mitigation:
https://ubuntu.com/security/CVE-2021-3714
CONFIG_KSM=y is set in yocto-kernel-cache (bsp/intel-x86 and the
paravirt_kvm fragments), so this is not a configuration exclusion.
It does however require two runtime opt-ins: ksm_run defaults to
KSM_RUN_STOP in mm/ksm.c, so ksmd must be started by the administrator,
and memory is only eligible if the process asks for it with
madvise(MADV_MERGEABLE) or prctl(PR_SET_MEMORY_MERGE).
CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
of leaving them undocumented
- disclosed AI assistance per the contributor guide
v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/
meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index aaba26fe..9012d328 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -199,3 +199,10 @@ CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
# https://www.openwall.com/lists/oss-security/2019/12/05/1
CVE_STATUS[CVE-2019-14899] = "upstream-wontfix: consequence of the default weak \
host model, no kernel fix exists or is planned, mitigated by firewall configuration"
+
+# Inherent to KSM deduplication, closed WONTFIX by Red Hat. Exposure needs
+# ksmd started at runtime (/sys/kernel/mm/ksm/run defaults to 0) and the
+# workload to opt in via MADV_MERGEABLE or prctl(PR_SET_MEMORY_MERGE).
+# https://bugzilla.redhat.com/show_bug.cgi?id=1931327
+CVE_STATUS[CVE-2021-3714] = "upstream-wontfix: inherent design limitation of \
+KSM page deduplication, closed WONTFIX by Red Hat, no upstream fix planned"
--
2.43.0
next prev parent reply other threads:[~2026-08-03 8:49 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 8:48 [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 01/10] cve-exclusion: set status for CVE-2019-14899 Junjie Cao
2026-08-03 8:48 ` Junjie Cao [this message]
2026-08-03 8:48 ` [OE-core][PATCH v2 03/10] cve-exclusion: set status for CVE-2021-3864 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 04/10] cve-exclusion: set status for CVE-2022-0400 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 05/10] cve-exclusion: set status for CVE-2022-1247 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 06/10] cve-exclusion: set status for CVE-2022-4543 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 07/10] cve-exclusion: set status for CVE-2023-3397 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 08/10] cve-exclusion: set status for CVE-2023-4010 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 09/10] cve-exclusion: set status for CVE-2023-6238 Junjie Cao
2026-08-03 8:48 ` [OE-core][PATCH v2 10/10] cve-exclusion: set status for CVE-2023-6240 Junjie Cao
2026-08-06 11:52 ` [OE-core][PATCH v2 00/10] cve-exclusion: triage ten kernel CVEs lacking upstream fix data Paul Barker
2026-08-10 10:19 ` Junjie Cao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260803084827.1348810-3-junjie.cao@linux.dev \
--to=junjie.cao@linux.dev \
--cc=Venkata.Navuduri@windriver.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=paul@pbarker.dev \
--cc=randy.macleod@windriver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.