CVE-2024-47727 (GCVE-0-2024-47727)
Vulnerability from cvelistv5
Published
2024-10-21 12:14
Modified
2026-08-05 11:39
Summary
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix "in-kernel MMIO" check TDX only supports kernel-initiated MMIO operations. The handle_mmio() function checks if the #VE exception occurred in the kernel and rejects the operation if it did not. However, userspace can deceive the kernel into performing MMIO on its behalf. For example, if userspace can point a syscall to an MMIO address, syscall does get_user() or put_user() on it, triggering MMIO #VE. The kernel will treat the #VE as in-kernel MMIO. Ensure that the target MMIO address is within the kernel before decoding instruction.
Impacted products
Vendor Product Version
Linux Linux Version: 31d58c4e557d46fa7f8557714250fb6f89c941ae
Version: 31d58c4e557d46fa7f8557714250fb6f89c941ae
Version: 31d58c4e557d46fa7f8557714250fb6f89c941ae
Version: 31d58c4e557d46fa7f8557714250fb6f89c941ae
Version: 31d58c4e557d46fa7f8557714250fb6f89c941ae
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-47727",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-21T13:01:01.673306Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-21T13:04:16.452Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:21:23.601Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/x86/coco/tdx/tdx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "25703a3c980e21548774eea8c8a87a75c5c8f58c",
              "status": "affected",
              "version": "31d58c4e557d46fa7f8557714250fb6f89c941ae",
              "versionType": "git"
            },
            {
              "lessThan": "4c0c5dcb5471de5fc8f0a1c4980e5815339e1cee",
              "status": "affected",
              "version": "31d58c4e557d46fa7f8557714250fb6f89c941ae",
              "versionType": "git"
            },
            {
              "lessThan": "18ecd5b74682839e7cdafb7cd1ec106df7baa18c",
              "status": "affected",
              "version": "31d58c4e557d46fa7f8557714250fb6f89c941ae",
              "versionType": "git"
            },
            {
              "lessThan": "bca2e29f7e26ce7c3522f8b324c0bd85612f68e3",
              "status": "affected",
              "version": "31d58c4e557d46fa7f8557714250fb6f89c941ae",
              "versionType": "git"
            },
            {
              "lessThan": "d4fc4d01471528da8a9797a065982e05090e1d81",
              "status": "affected",
              "version": "31d58c4e557d46fa7f8557714250fb6f89c941ae",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/x86/coco/tdx/tdx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "lessThan": "5.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.54",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.13",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.2",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Fix \"in-kernel MMIO\" check\n\nTDX only supports kernel-initiated MMIO operations. The handle_mmio()\nfunction checks if the #VE exception occurred in the kernel and rejects\nthe operation if it did not.\n\nHowever, userspace can deceive the kernel into performing MMIO on its\nbehalf. For example, if userspace can point a syscall to an MMIO address,\nsyscall does get_user() or put_user() on it, triggering MMIO #VE. The\nkernel will treat the #VE as in-kernel MMIO.\n\nEnsure that the target MMIO address is within the kernel before decoding\ninstruction."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires a local process inside the TDX guest to issue syscalls with a pointer into an MMIO/host-visible mapping; there is no network-reachable path to the #VE handler.\nAC:L - The attacker fully controls both the mapping and the syscall pointer, and get_user()/put_user() emit exactly the mov encodings that insn_decode_mmio() accepts, so the MMIO hypercall is triggered deterministically with no race or unpredictable state.\nPR:L - An ordinary unprivileged guest account suffices \u2014 any mapping of a device BAR or of DMA-coherent (decrypted/shared) memory exposed by a driver mmap works, and the untrusted VMM can force EPT-violation #VEs on shared pages at will.\nUI:N - The attacking process performs the mmap and the syscall itself; no other user or victim action is involved.\nS:U - The boundary bypassed is guest-userspace to guest-kernel within the same OS authority; this is not a guest-to-host escape or an IOMMU/DMA boundary bypass.\nC:H - Userspace obtains an unauthorized MMIO read primitive against device registers and forces kernel-context data out through TDVMCALL to the untrusted VMM, defeating the TD confidentiality guarantee; it is also the reachable path to the uninitialized-stack leak in mmio_read().\nI:H - The bug yields an unprivileged MMIO write primitive to device/hypervisor-visible registers (doorbells, DMA and control registers), and VMM-supplied read data is written directly into the kernel\u0027s pt_regs and acted upon mid-syscall.\nA:H - Unauthorized MMIO writes can misprogram or wedge virtual devices, and the userspace-reachable WARN_ON_ONCE()/-EIO paths reach ve_raise_fault() and die_addr(), producing an oops or a full panic under panic_on_warn."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:39:46.427Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/25703a3c980e21548774eea8c8a87a75c5c8f58c"
        },
        {
          "url": "https://git.kernel.org/stable/c/4c0c5dcb5471de5fc8f0a1c4980e5815339e1cee"
        },
        {
          "url": "https://git.kernel.org/stable/c/18ecd5b74682839e7cdafb7cd1ec106df7baa18c"
        },
        {
          "url": "https://git.kernel.org/stable/c/bca2e29f7e26ce7c3522f8b324c0bd85612f68e3"
        },
        {
          "url": "https://git.kernel.org/stable/c/d4fc4d01471528da8a9797a065982e05090e1d81"
        }
      ],
      "title": "x86/tdx: Fix \"in-kernel MMIO\" check",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-47727",
    "datePublished": "2024-10-21T12:14:00.330Z",
    "dateReserved": "2024-09-30T16:00:12.957Z",
    "dateUpdated": "2026-08-05T11:39:46.427Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:21:23.601Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-47727\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-21T13:01:01.673306Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-21T13:01:04.889Z\"}}], \"cna\": {\"title\": \"x86/tdx: Fix \\\"in-kernel MMIO\\\" check\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"31d58c4e557d46fa7f8557714250fb6f89c941ae\", \"lessThan\": \"25703a3c980e21548774eea8c8a87a75c5c8f58c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"31d58c4e557d46fa7f8557714250fb6f89c941ae\", \"lessThan\": \"4c0c5dcb5471de5fc8f0a1c4980e5815339e1cee\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"31d58c4e557d46fa7f8557714250fb6f89c941ae\", \"lessThan\": \"18ecd5b74682839e7cdafb7cd1ec106df7baa18c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"31d58c4e557d46fa7f8557714250fb6f89c941ae\", \"lessThan\": \"bca2e29f7e26ce7c3522f8b324c0bd85612f68e3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"31d58c4e557d46fa7f8557714250fb6f89c941ae\", \"lessThan\": \"d4fc4d01471528da8a9797a065982e05090e1d81\", \"versionType\": \"git\"}], \"programFiles\": [\"arch/x86/coco/tdx/tdx.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.19\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.19\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.54\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.13\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"arch/x86/coco/tdx/tdx.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/25703a3c980e21548774eea8c8a87a75c5c8f58c\"}, {\"url\": \"https://git.kernel.org/stable/c/4c0c5dcb5471de5fc8f0a1c4980e5815339e1cee\"}, {\"url\": \"https://git.kernel.org/stable/c/18ecd5b74682839e7cdafb7cd1ec106df7baa18c\"}, {\"url\": \"https://git.kernel.org/stable/c/bca2e29f7e26ce7c3522f8b324c0bd85612f68e3\"}, {\"url\": \"https://git.kernel.org/stable/c/d4fc4d01471528da8a9797a065982e05090e1d81\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nx86/tdx: Fix \\\"in-kernel MMIO\\\" check\\n\\nTDX only supports kernel-initiated MMIO operations. The handle_mmio()\\nfunction checks if the #VE exception occurred in the kernel and rejects\\nthe operation if it did not.\\n\\nHowever, userspace can deceive the kernel into performing MMIO on its\\nbehalf. For example, if userspace can point a syscall to an MMIO address,\\nsyscall does get_user() or put_user() on it, triggering MMIO #VE. The\\nkernel will treat the #VE as in-kernel MMIO.\\n\\nEnsure that the target MMIO address is within the kernel before decoding\\ninstruction.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"5.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.54\", \"versionStartIncluding\": \"5.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.13\", \"versionStartIncluding\": \"5.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.2\", \"versionStartIncluding\": \"5.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"5.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:38:22.222Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-47727\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-11-03T22:21:23.601Z\", \"dateReserved\": \"2024-09-30T16:00:12.957Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T12:14:00.330Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…