CVE-2024-26598
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operation that…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operation that invalidates the cache, such as a DISCARD ITS command. The root of the problem is that vgic_its_check_cache() does not elevate the refcount on the vgic_irq before dropping the lock that serializes refcount changes. Have vgic_its_check_cache() raise the refcount on the returned vgic_irq and add the corresponding decrement after queueing the interrupt.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/12c2759ab1343c124ed46ba48f27bd1ef5d2dff4Patch
- https://git.kernel.org/stable/c/65b201bf3e9af1b0254243a5881390eda56f72d1Patch
- https://git.kernel.org/stable/c/ad362fe07fecf0aba839ff2cc59a3617bd42c33fPatch
- https://git.kernel.org/stable/c/ba7be666740847d967822bed15500656b26bc703Patch
- https://git.kernel.org/stable/c/d04acadb6490aa3314f9c9e087691e55de153b88Patch
- https://git.kernel.org/stable/c/dba788e25f05209adf2b0175eb1691dc89fb1ba6Patch
- https://git.kernel.org/stable/c/dd3956a1b3dd11f46488c928cb890d6937d1ca80Patch
- https://git.kernel.org/stable/c/12c2759ab1343c124ed46ba48f27bd1ef5d2dff4Patch
- https://git.kernel.org/stable/c/65b201bf3e9af1b0254243a5881390eda56f72d1Patch
- https://git.kernel.org/stable/c/ad362fe07fecf0aba839ff2cc59a3617bd42c33fPatch
- https://git.kernel.org/stable/c/ba7be666740847d967822bed15500656b26bc703Patch
- https://git.kernel.org/stable/c/d04acadb6490aa3314f9c9e087691e55de153b88Patch
- https://git.kernel.org/stable/c/dba788e25f05209adf2b0175eb1691dc89fb1ba6Patch
- https://git.kernel.org/stable/c/dd3956a1b3dd11f46488c928cb890d6937d1ca80Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.