Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-41070— KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在kvm_spapr_tce_attach_iommu_group函数中,存在释放后重用问题。

CVSS 7.8 · High EPSS 0.23% · P13

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 121f80ba68f1a5779a36d7b3247206e60e0a7418< be847bb20c809de8ac124431b556f244400b0491 affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< 4cdf6926f443c84f680213c7aafbe6f91a5fcbc0 affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< b26c8c85463ef27a522d24fcd05651f0bb039e47 affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< 5f856023971f97fff74cfaf21b48ec320147b50a affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< 82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< 9975f93c760a32453d7639cf6fcf3f73b4e71ffe affected
121f80ba68f1a5779a36d7b3247206e60e0a7418< a986fa57fd81a1430e00b3c6cf8a325d6f894a63 affected
4.12 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-41070

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group() Al reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group(). It looks up `stt` from tablefd, but then continues to use it after doing fdput() on the returned fd. After the fdput() the tablefd is free to be closed by another thread. The close calls kvm_spapr_tce_release() and then release_spapr_tce_table() (via call_rcu()) which frees `stt`. Although there are calls to rcu_read_lock() in kvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent the UAF, because `stt` is used outside the locked regions. With an artifcial delay after the fdput() and a userspace program which triggers the race, KASAN detects the UAF: BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505 CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1 Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV Call Trace: dump_stack_lvl+0xb4/0x108 (unreliable) print_report+0x2b4/0x6ec kasan_report+0x118/0x2b0 __asan_load4+0xb8/0xd0 kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] kvm_vfio_set_attr+0x524/0xac0 [kvm] kvm_device_ioctl+0x144/0x240 [kvm] sys_ioctl+0x62c/0x1810 system_call_exception+0x190/0x440 system_call_vectored_common+0x15c/0x2ec ... Freed by task 0: ... kfree+0xec/0x3e0 release_spapr_tce_table+0xd4/0x11c [kvm] rcu_core+0x568/0x16a0 handle_softirqs+0x23c/0x920 do_softirq_own_stack+0x6c/0x90 do_softirq_own_stack+0x58/0x90 __irq_exit_rcu+0x218/0x2d0 irq_exit+0x30/0x80 arch_local_irq_restore+0x128/0x230 arch_local_irq_enable+0x1c/0x30 cpuidle_enter_state+0x134/0x5cc cpuidle_enter+0x6c/0xb0 call_cpuidle+0x7c/0x100 do_idle+0x394/0x410 cpu_startup_entry+0x60/0x70 start_secondary+0x3fc/0x410 start_secondary_prolog+0x10/0x14 Fix it by delaying the fdput() until `stt` is no longer in use, which is effectively the entire function. To keep the patch minimal add a call to fdput() at each of the existing return paths. Future work can convert the function to goto or __cleanup style cleanup. With the fix in place the test case no longer triggers the UAF.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在kvm_spapr_tce_attach_iommu_group函数中,存在释放后重用问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 121f80ba68f1a5779a36d7b3247206e60e0a7418 ~ be847bb20c809de8ac124431b556f244400b0491 -
Linux Linux 4.12 -

II. Public POCs for CVE-2024-41070

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-41070

请登录查看更多情报信息。

Other References for CVE-2024-41070 (7)

Same Patch Batch · Linux · 2024-07-29 · 121 CVEs total

CVE-2024-41040 9.8 CRITICAL net/sched: Fix UAF when resolving a clash
CVE-2024-41073 9.8 CRITICAL nvme: avoid double free special payload
CVE-2024-41081 9.8 CRITICAL ila: block BH in ila_output()
CVE-2024-41091 8.8 HIGH tun: add missing verification for short frame
CVE-2024-41090 8.8 HIGH tap: add missing verification for short frame
CVE-2024-41062 8.8 HIGH bluetooth/l2cap: sync sock recv cb and release
CVE-2024-41046 8.8 HIGH net: ethernet: lantiq_etop: fix double free in detach
CVE-2024-42083 8.8 HIGH ionic: fix kernel panic due to multi-buffer handling
CVE-2024-42064 7.8 HIGH drm/amd/display: Skip pipe if the pipe idx not set properly
CVE-2024-41069 7.8 HIGH ASoC: topology: Fix references to freed memory
CVE-2024-41041 7.8 HIGH udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
CVE-2024-41045 7.8 HIGH bpf: Defer work in bpf_timer_cancel_and_free
CVE-2024-41049 7.8 HIGH filelock: fix potential use-after-free in posix_lock_inode
CVE-2024-42066 7.8 HIGH drm/xe: Fix potential integer overflow in page size calculation
CVE-2024-41051 7.8 HIGH cachefiles: wait for ondemand_object_worker to finish when dropping object
CVE-2024-41064 7.8 HIGH powerpc/eeh: avoid possible crash when edev->pdev changes
CVE-2024-41059 7.8 HIGH hfsplus: fix uninit-value in copy_name
CVE-2024-42075 7.8 HIGH bpf: Fix remap of arena.
CVE-2024-41060 7.8 HIGH drm/radeon: check bo_va->bo is non-NULL before using it
CVE-2024-42072 7.8 HIGH bpf: Fix may_goto with negative offset.

Showing top 20 of 121 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-41070

No comments yet


Leave a comment