[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2024073028-CVE-2024-42134-99d7@gregkh>
Date: Tue, 30 Jul 2024 09:47:52 +0200
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
Subject: CVE-2024-42134: virtio-pci: Check if is_avq is NULL
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
virtio-pci: Check if is_avq is NULL
[bug]
In the virtio_pci_common.c function vp_del_vqs, vp_dev->is_avq is involved
to determine whether it is admin virtqueue, but this function vp_dev->is_avq
may be empty. For installations, virtio_pci_legacy does not assign a value
to vp_dev->is_avq.
[fix]
Check whether it is vp_dev->is_avq before use.
[test]
Test with virsh Attach device
Before this patch, the following command would crash the guest system
After applying the patch, everything seems to be working fine.
The Linux kernel CVE team has assigned CVE-2024-42134 to this issue.
Affected and fixed versions
===========================
Fixed in 6.9.9 with commit 5e2024b0b9b3
Fixed in 6.10 with commit c8fae27d141a
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2024-42134
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/virtio/virtio_pci_common.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/5e2024b0b9b3d5709e3f7e9b92951d7e29154106
https://git.kernel.org/stable/c/c8fae27d141a32a1624d0d0d5419d94252824498
Powered by blists - more mailing lists