CVE-2024-41070 (GCVE-0-2024-41070)
Vulnerability from cvelistv5
Published
2024-07-29 14:57
Modified
2026-08-05 11:35
Summary
In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group() Al reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group(). It looks up `stt` from tablefd, but then continues to use it after doing fdput() on the returned fd. After the fdput() the tablefd is free to be closed by another thread. The close calls kvm_spapr_tce_release() and then release_spapr_tce_table() (via call_rcu()) which frees `stt`. Although there are calls to rcu_read_lock() in kvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent the UAF, because `stt` is used outside the locked regions. With an artifcial delay after the fdput() and a userspace program which triggers the race, KASAN detects the UAF: BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505 CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1 Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV Call Trace: dump_stack_lvl+0xb4/0x108 (unreliable) print_report+0x2b4/0x6ec kasan_report+0x118/0x2b0 __asan_load4+0xb8/0xd0 kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] kvm_vfio_set_attr+0x524/0xac0 [kvm] kvm_device_ioctl+0x144/0x240 [kvm] sys_ioctl+0x62c/0x1810 system_call_exception+0x190/0x440 system_call_vectored_common+0x15c/0x2ec ... Freed by task 0: ... kfree+0xec/0x3e0 release_spapr_tce_table+0xd4/0x11c [kvm] rcu_core+0x568/0x16a0 handle_softirqs+0x23c/0x920 do_softirq_own_stack+0x6c/0x90 do_softirq_own_stack+0x58/0x90 __irq_exit_rcu+0x218/0x2d0 irq_exit+0x30/0x80 arch_local_irq_restore+0x128/0x230 arch_local_irq_enable+0x1c/0x30 cpuidle_enter_state+0x134/0x5cc cpuidle_enter+0x6c/0xb0 call_cpuidle+0x7c/0x100 do_idle+0x394/0x410 cpu_startup_entry+0x60/0x70 start_secondary+0x3fc/0x410 start_secondary_prolog+0x10/0x14 Fix it by delaying the fdput() until `stt` is no longer in use, which is effectively the entire function. To keep the patch minimal add a call to fdput() at each of the existing return paths. Future work can convert the function to goto or __cleanup style cleanup. With the fix in place the test case no longer triggers the UAF.
Impacted products
Vendor Product Version
Linux Linux Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Version: 121f80ba68f1a5779a36d7b3247206e60e0a7418
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:00:20.787Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/be847bb20c809de8ac124431b556f244400b0491"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4cdf6926f443c84f680213c7aafbe6f91a5fcbc0"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/b26c8c85463ef27a522d24fcd05651f0bb039e47"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/5f856023971f97fff74cfaf21b48ec320147b50a"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9975f93c760a32453d7639cf6fcf3f73b4e71ffe"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a986fa57fd81a1430e00b3c6cf8a325d6f894a63"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-41070",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:21:40.187466Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:34:00.946Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/powerpc/kvm/book3s_64_vio.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "be847bb20c809de8ac124431b556f244400b0491",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "4cdf6926f443c84f680213c7aafbe6f91a5fcbc0",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "b26c8c85463ef27a522d24fcd05651f0bb039e47",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "5f856023971f97fff74cfaf21b48ec320147b50a",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "9975f93c760a32453d7639cf6fcf3f73b4e71ffe",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            },
            {
              "lessThan": "a986fa57fd81a1430e00b3c6cf8a325d6f894a63",
              "status": "affected",
              "version": "121f80ba68f1a5779a36d7b3247206e60e0a7418",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/powerpc/kvm/book3s_64_vio.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.12"
            },
            {
              "lessThan": "4.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.281",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.223",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.164",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.101",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.42",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.281",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.223",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.164",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.101",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.42",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.11",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()\n\nAl reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group().\n\nIt looks up `stt` from tablefd, but then continues to use it after doing\nfdput() on the returned fd. After the fdput() the tablefd is free to be\nclosed by another thread. The close calls kvm_spapr_tce_release() and\nthen release_spapr_tce_table() (via call_rcu()) which frees `stt`.\n\nAlthough there are calls to rcu_read_lock() in\nkvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent\nthe UAF, because `stt` is used outside the locked regions.\n\nWith an artifcial delay after the fdput() and a userspace program which\ntriggers the race, KASAN detects the UAF:\n\n  BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\n  Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505\n  CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1\n  Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV\n  Call Trace:\n    dump_stack_lvl+0xb4/0x108 (unreliable)\n    print_report+0x2b4/0x6ec\n    kasan_report+0x118/0x2b0\n    __asan_load4+0xb8/0xd0\n    kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\n    kvm_vfio_set_attr+0x524/0xac0 [kvm]\n    kvm_device_ioctl+0x144/0x240 [kvm]\n    sys_ioctl+0x62c/0x1810\n    system_call_exception+0x190/0x440\n    system_call_vectored_common+0x15c/0x2ec\n  ...\n  Freed by task 0:\n   ...\n   kfree+0xec/0x3e0\n   release_spapr_tce_table+0xd4/0x11c [kvm]\n   rcu_core+0x568/0x16a0\n   handle_softirqs+0x23c/0x920\n   do_softirq_own_stack+0x6c/0x90\n   do_softirq_own_stack+0x58/0x90\n   __irq_exit_rcu+0x218/0x2d0\n   irq_exit+0x30/0x80\n   arch_local_irq_restore+0x128/0x230\n   arch_local_irq_enable+0x1c/0x30\n   cpuidle_enter_state+0x134/0x5cc\n   cpuidle_enter+0x6c/0xb0\n   call_cpuidle+0x7c/0x100\n   do_idle+0x394/0x410\n   cpu_startup_entry+0x60/0x70\n   start_secondary+0x3fc/0x410\n   start_secondary_prolog+0x10/0x14\n\nFix it by delaying the fdput() until `stt` is no longer in use, which\nis effectively the entire function. To keep the patch minimal add a call\nto fdput() at each of the existing return paths. Future work can convert\nthe function to goto or __cleanup style cleanup.\n\nWith the fix in place the test case no longer triggers the UAF."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is reached only through `ioctl(KVM_SET_DEVICE_ATTR, KVM_DEV_VFIO_GROUP_SET_SPAPR_TCE)` on a KVM VFIO device fd, requiring local access to /dev/kvm and /dev/vfio on a POWER Book3S HV host. No remote or adjacent-network input reaches this path.\nAC:L - The attacker owns both sides of the race \u2014 one thread issues the ioctl while another calls `close(tablefd)` \u2014 and the window between `fdput()` and the uses of `stt` contains a sleepable `kzalloc(GFP_KERNEL)` that can be stretched arbitrarily under attacker-induced memory pressure. Failed attempts merely return an errno, so the race can be retried indefinitely, and the attacker also chooses the slab bucket via `KVM_CREATE_SPAPR_TCE_64`\u0027s `size` argument.\nPR:L - No `capable()` or `CAP_*` check exists anywhere along the path in `book3s_64_vio.c` or `virt/kvm/vfio.c`; the attacker only needs file access to /dev/kvm and a VFIO group node, which libvirt routinely grants to the unprivileged QEMU user in the standard PPC64 device-passthrough deployment. A compromised VMM process that has escaped a guest into QEMU holds exactly these descriptors, so real root is not required.\nUI:N - Both the ioctl and the racing `close()` are performed entirely by the attacker\u0027s own threads. No administrator or victim action is involved.\nS:U - The attacker is a host-local userspace process and the corrupted memory is host kernel heap, so the vulnerable and impacted components share one security authority. A guest cannot reach `kvm_vfio_set_attr`, so this is not a guest-to-host escape.\nC:H - The freed `stt` is read after free (`page_shift`, `offset`, `size`), and the `next-\u003eprev = new` write derived from freed-memory contents gives an arbitrary kernel-write primitive that is readily converted into arbitrary kernel-memory disclosure. Attacker-controlled slab-bucket selection makes the reallocation reliable enough to build a read primitive.\nI:H - `list_add_rcu(\u0026stit-\u003enext, \u0026stt-\u003eiommu_tables)` writes into the freed object and additionally performs `next-\u003eprev = new` where `next` is loaded from attacker-reallocated memory, yielding a write of a kernel heap pointer to an arbitrary address. With `__list_add_valid()` a no-op on default configs, this is a classic path to control-flow hijack and privilege escalation.\nA:H - The slab use-after-free corrupts the kernel heap and the wild `next-\u003eprev` store into an unrelated address readily produces an oops or panic; on `CONFIG_LIST_HARDENED` kernels the corrupted list triggers a BUG. The attacker can repeat the trigger at will to keep the host down."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:35:11.092Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/be847bb20c809de8ac124431b556f244400b0491"
        },
        {
          "url": "https://git.kernel.org/stable/c/4cdf6926f443c84f680213c7aafbe6f91a5fcbc0"
        },
        {
          "url": "https://git.kernel.org/stable/c/b26c8c85463ef27a522d24fcd05651f0bb039e47"
        },
        {
          "url": "https://git.kernel.org/stable/c/5f856023971f97fff74cfaf21b48ec320147b50a"
        },
        {
          "url": "https://git.kernel.org/stable/c/82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf"
        },
        {
          "url": "https://git.kernel.org/stable/c/9975f93c760a32453d7639cf6fcf3f73b4e71ffe"
        },
        {
          "url": "https://git.kernel.org/stable/c/a986fa57fd81a1430e00b3c6cf8a325d6f894a63"
        }
      ],
      "title": "KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-41070",
    "datePublished": "2024-07-29T14:57:30.952Z",
    "dateReserved": "2024-07-12T12:17:45.630Z",
    "dateUpdated": "2026-08-05T11:35:11.092Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/be847bb20c809de8ac124431b556f244400b0491\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4cdf6926f443c84f680213c7aafbe6f91a5fcbc0\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/b26c8c85463ef27a522d24fcd05651f0bb039e47\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/5f856023971f97fff74cfaf21b48ec320147b50a\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/9975f93c760a32453d7639cf6fcf3f73b4e71ffe\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a986fa57fd81a1430e00b3c6cf8a325d6f894a63\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T04:46:52.443Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-41070\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:21:40.187466Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:20.173Z\"}}], \"cna\": {\"title\": \"KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"be847bb20c809de8ac124431b556f244400b0491\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"4cdf6926f443c84f680213c7aafbe6f91a5fcbc0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"b26c8c85463ef27a522d24fcd05651f0bb039e47\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"5f856023971f97fff74cfaf21b48ec320147b50a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"9975f93c760a32453d7639cf6fcf3f73b4e71ffe\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"121f80ba68f1a5779a36d7b3247206e60e0a7418\", \"lessThan\": \"a986fa57fd81a1430e00b3c6cf8a325d6f894a63\", \"versionType\": \"git\"}], \"programFiles\": [\"arch/powerpc/kvm/book3s_64_vio.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.12\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.12\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.281\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.223\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.164\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.101\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.42\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"arch/powerpc/kvm/book3s_64_vio.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/be847bb20c809de8ac124431b556f244400b0491\"}, {\"url\": \"https://git.kernel.org/stable/c/4cdf6926f443c84f680213c7aafbe6f91a5fcbc0\"}, {\"url\": \"https://git.kernel.org/stable/c/b26c8c85463ef27a522d24fcd05651f0bb039e47\"}, {\"url\": \"https://git.kernel.org/stable/c/5f856023971f97fff74cfaf21b48ec320147b50a\"}, {\"url\": \"https://git.kernel.org/stable/c/82c7a4cf14aa866f8f7f09e662b02eddc49ee0bf\"}, {\"url\": \"https://git.kernel.org/stable/c/9975f93c760a32453d7639cf6fcf3f73b4e71ffe\"}, {\"url\": \"https://git.kernel.org/stable/c/a986fa57fd81a1430e00b3c6cf8a325d6f894a63\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nKVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()\\n\\nAl reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group().\\n\\nIt looks up `stt` from tablefd, but then continues to use it after doing\\nfdput() on the returned fd. After the fdput() the tablefd is free to be\\nclosed by another thread. The close calls kvm_spapr_tce_release() and\\nthen release_spapr_tce_table() (via call_rcu()) which frees `stt`.\\n\\nAlthough there are calls to rcu_read_lock() in\\nkvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent\\nthe UAF, because `stt` is used outside the locked regions.\\n\\nWith an artifcial delay after the fdput() and a userspace program which\\ntriggers the race, KASAN detects the UAF:\\n\\n  BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\\n  Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505\\n  CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1\\n  Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV\\n  Call Trace:\\n    dump_stack_lvl+0xb4/0x108 (unreliable)\\n    print_report+0x2b4/0x6ec\\n    kasan_report+0x118/0x2b0\\n    __asan_load4+0xb8/0xd0\\n    kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\\n    kvm_vfio_set_attr+0x524/0xac0 [kvm]\\n    kvm_device_ioctl+0x144/0x240 [kvm]\\n    sys_ioctl+0x62c/0x1810\\n    system_call_exception+0x190/0x440\\n    system_call_vectored_common+0x15c/0x2ec\\n  ...\\n  Freed by task 0:\\n   ...\\n   kfree+0xec/0x3e0\\n   release_spapr_tce_table+0xd4/0x11c [kvm]\\n   rcu_core+0x568/0x16a0\\n   handle_softirqs+0x23c/0x920\\n   do_softirq_own_stack+0x6c/0x90\\n   do_softirq_own_stack+0x58/0x90\\n   __irq_exit_rcu+0x218/0x2d0\\n   irq_exit+0x30/0x80\\n   arch_local_irq_restore+0x128/0x230\\n   arch_local_irq_enable+0x1c/0x30\\n   cpuidle_enter_state+0x134/0x5cc\\n   cpuidle_enter+0x6c/0xb0\\n   call_cpuidle+0x7c/0x100\\n   do_idle+0x394/0x410\\n   cpu_startup_entry+0x60/0x70\\n   start_secondary+0x3fc/0x410\\n   start_secondary_prolog+0x10/0x14\\n\\nFix it by delaying the fdput() until `stt` is no longer in use, which\\nis effectively the entire function. To keep the patch minimal add a call\\nto fdput() at each of the existing return paths. Future work can convert\\nthe function to goto or __cleanup style cleanup.\\n\\nWith the fix in place the test case no longer triggers the UAF.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.281\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.223\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.164\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.101\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.42\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.11\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"4.12\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-21T09:12:52.680Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-41070\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-21T09:12:52.680Z\", \"dateReserved\": \"2024-07-12T12:17:45.630Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-07-29T14:57:30.952Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…